{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/query-wrangler-1.5.57/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-14498"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Query Wrangler (1.5.57)"],"_cs_severities":["high"],"_cs_tags":["wordpress","rce","plugin-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Query Wrangler plugin for WordPress, in versions up to and including 1.5.57, contains a critical Remote Code Execution (RCE) vulnerability identified as CVE-2026-14498. The flaw resides in the wp_ajax_qw_form_ajax handler, which processes requests without performing nonce verification or capability checks. An attacker with minimal privileges (subscriber level) can manipulate the 'options' parameter to inject malicious query configurations. Because these options are passed directly to the PHP call_user_func_array() function with insufficient validation beyond a function_exists() check, an attacker can trigger the execution of arbitrary server-side functions. This vulnerability is particularly dangerous because the query_id used in the handler is an enumerable integer, making it trivial for an attacker to identify an existing target row in the database and execute the exploit payload.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-14498 grants an attacker the ability to execute arbitrary PHP code on the underlying web server. This can lead to full site compromise, data exfiltration, and lateral movement within the hosting environment. While the vulnerability requires subscriber-level authentication, the low barrier to entry and the ease of identifying targets via query_id enumeration significantly increase the risk profile for WordPress installations running this plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Query Wrangler plugin to the latest version immediately to remediate CVE-2026-14498.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests directed at wp-admin/admin-ajax.php involving the qw_form_ajax action.\u003c/li\u003e\n\u003cli\u003eAudit subscriber-level account activity for patterns of repeated requests targeting sequential query_id integers.\u003c/li\u003e\n\u003cli\u003eApply the following webserver detection logic to identify potential exploitation attempts in environment logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T06:24:37Z","date_published":"2026-08-16T06:24:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-query-wrangler-rce/","summary":"An unauthenticated-accessible AJAX handler in Query Wrangler versions 1.5.57 and below allows authenticated attackers to perform remote code execution via object injection and callback manipulation.","title":"Remote Code Execution in Query Wrangler WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-query-wrangler-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Query Wrangler (1.5.57)","version":"https://jsonfeed.org/version/1.1"}