Description
Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
Published: 2026-08-06
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Remote Code Execution vulnerability exists in the Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin version 2.1.3 and earlier. The flaw allows an attacker to inject and execute arbitrary code through the plugin’s input handling, potentially compromising the entire WordPress installation. The associated weakness is classified as CWE‑94, indicating an improper handling of evaluated code. The impact includes full control over the affected server, data theft, defacement, and further lateral movement. The vulnerability is severe because it does not require authentication to exploit.

Affected Systems

WordPress sites that have the Spider Analyser plugin installed with a version equal to or older than 2.1.3. The plugin is distributed by wbolt.com and is used to analyze search engine spiders. Any WordPress installation running the impacted plugin becomes a valid target.

Risk and Exploitability

The CVSS score of 10 reflects a critical severity. Although the EPSS score is not available, the lack of exploitation data does not diminish the risk; the high CVSS score indicates that an attacker could easily gain remote code execution. The vulnerability is not listed in the CISA KEV catalog, but the unauthenticated execution vector means that an attacker could compromise a site without user interaction. If the plugin is accessible via the public web interface, the attack can be launched from any remote location.

Generated by OpenCVE AI on August 6, 2026 at 15:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Spider Analyser plugin to the latest release that removes the code‑execution flaw.
  • If the plugin is not required, uninstall or disable it entirely to eliminate the attack surface.
  • Conduct a manual file integrity check of the plugin directory and audit any recently added files for malicious content.

Generated by OpenCVE AI on August 6, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wbolt.com
Wbolt.com spider Analyser &#8211; Wordpress搜索引擎蜘蛛分析插件
Wordpress
Wordpress wordpress
Vendors & Products Wbolt.com
Wbolt.com spider Analyser &#8211; Wordpress搜索引擎蜘蛛分析插件
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
Title WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Wbolt.com Spider Analyser &#8211; Wordpress搜索引擎蜘蛛分析插件
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T15:36:06.805Z

Reserved: 2026-07-22T08:54:23.961Z

Link: CVE-2026-65553

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:17.557

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-65553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:59:51Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')