CyberRota Analysis
AI-GeneratedThe DoLeads Integrator and wp2epub plugins for WordPress versions up to 0.65 are vulnerable to remote code execution (RCE) due to improper handling of unclosed extensions, allowing unauthorized users to install malicious plugins. This critical vulnerability poses a significant risk to any WordPress site using these plugins, potentially leading to full system compromise. WordPress administrators and security teams should prioritize immediate updates or removal of these plugins to mitigate the threat.
Original NVD Description
The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.