Impact
The vulnerability permits a subscriber to execute arbitrary PHP code within a WordPress site powered by the RepairBuddy plugin. This core flaw, categorized as CWE‑94, enables attackers to inject malicious code that can compromise confidentiality, integrity, and availability of the entire site. The described impact is the execution of arbitrary scripts, which could lead to full site takeover, data exfiltration, or installation of persistence mechanisms.
Affected Systems
Ateeq Rafeeq’s RepairBuddy plugin in WordPress installations is impacted when the plugin version is 4.1224 or earlier. No specific sub‐versions are detailed, so all releases up to and including 4.1224 should be considered vulnerable until the fix is applied. The plugin is used within WordPress sites that rely on its repair features.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity threat. EPSS data is not available, so the likelihood of exploitation cannot be quantified, but the absence of an EPSS score does not reduce concern, as the flaw allows unrestricted code execution. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Attackers would need to reach the subscription flows of the plugin, likely through authenticated or unauthenticated entry points, to inject code. Once injected, the attacker can run arbitrary PHP, leading to compromise of the WordPress installation.
OpenCVE Enrichment