SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-4375

CRITICAL · CVSS 9 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The DoLeads Integrator and wp2epub plugins for WordPress versions up to 0.65 are vulnerable to remote code execution (RCE) due to improper handling of unclosed extensions, allowing unauthorized users to install malicious plugins. This critical vulnerability poses a significant risk to any WordPress site using these plugins, potentially leading to full system compromise. WordPress administrators and security teams should prioritize immediate updates or removal of these plugins to mitigate the threat.

CVE
CVE-2026-4375
Severity
CRITICAL
CVSS
9
EPSS
0.25%
WordPress

Original NVD Description

The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.