WP Query Console Plugin for WordPress <= 1.0 – Remote Code Execution Vulnerability

ISGroup Cybersecurity

The WP Query Console plugin for WordPress has a critical Remote Code Execution (RCE) vulnerability affecting all versions up to and including 1.0. This vulnerability is unauthenticated, which allows attackers to execute arbitrary code without requiring prior access. A proof-of-concept exploit is publicly available, significantly increasing the likelihood of exploitation.

Patchstack has classified this vulnerability as highly dangerous, with a CVSS score of 10, and stated that “mass exploitation is expected.”

Productwp-query-console
Date2024-12-03 15:20:17
Information
  • Trending

Technical Summary

The WP Query Console plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 1.0. This flaw allows unauthenticated attackers to execute arbitrary code on the server, potentially leading to a full compromise of the website and the hosting environment.

Recommendations

Since no fix is currently available and the plugin has not been maintained or updated for seven years, it is recommended to immediately deactivate and uninstall the WP Query Console plugin.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert