Remote Code Execution Vulnerability in Query Wrangler Plugin for WordPress
CVE-2026-73992

9.9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-73992?

The Query Wrangler plugin for WordPress, versions 1.5.57 and earlier, is susceptible to a remote code execution vulnerability that allows an attacker to execute arbitrary code remotely. This critical flaw can potentially compromise the integrity of the website, leading to unauthorized access and control. Website owners using vulnerable versions are advised to update to mitigated versions immediately to protect against potential exploitation.

Affected Version(s)

Query Wrangler <= 1.5.57

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hhhai | Patchstack Bug Bounty Program
.