The WP Query Console plugin for WordPress has a critical Remote Code Execution (RCE) vulnerability affecting all versions up to and including 1.0. This vulnerability is unauthenticated, which allows attackers to execute arbitrary code without requiring prior access. A proof-of-concept exploit is publicly available, significantly increasing the likelihood of exploitation.
Patchstack has classified this vulnerability as highly dangerous, with a CVSS score of 10, and stated that “mass exploitation is expected.”
| Product | wp-query-console |
| Date | 2024-12-03 15:20:17 |
| Information |
|
Technical Summary
The WP Query Console plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 1.0. This flaw allows unauthenticated attackers to execute arbitrary code on the server, potentially leading to a full compromise of the website and the hosting environment.
Recommendations
Since no fix is currently available and the plugin has not been maintained or updated for seven years, it is recommended to immediately deactivate and uninstall the WP Query Console plugin.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
