ZeroHour

CVE-2024-50498

niche

Unauthenticated Code Injection in WordPress WP Query Console Plugin

CVSS 3.1
9.8 critical
EPSS
53%p99
Published
()
Modified
AI analysis

CVE-2024-50498 is an improper control of code generation (CWE-94) flaw in the WP Query Console WordPress plugin by Ajit Bohra/LUBUS, allowing remote code injection. According to the CVSS vector, it is exploitable over the network with low complexity, no privileges and no user interaction, meaning an unauthenticated attacker can trigger it by sending a crafted request to an affected site. Successful exploitation yields full remote code execution impact (high confidentiality, integrity and availability), letting the attacker run arbitrary code on the WordPress host. Any WordPress site running WP Query Console version 1.0 or earlier is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, though its EPSS score is high (~53% chance of exploitation within 30 days) and related reporting describes attackers chaining WordPress plugin flaws (e.g., the Hunk Companion issue) to silently install vulnerable plugins, which could bring this plugin onto otherwise unaffected sites.

What to do: Update WP Query Console to a version newer than 1.0 (the latest patched release) or deactivate and delete the plugin if it is not actively needed, since it is a developer tool rarely required in production. Internet-facing WordPress sites should be prioritized given the critical severity and high EPSS score. Check whether the related Hunk Companion plugin flaw was used to silently install WP Query Console or other vulnerable plugins on your sites.

Affected
lubus (Ajit Bohra) WP Query Console (WordPress plugin)from n/a through 1.0 (all versions up to and including 1.0)
Estimated exposure
nichelikely low hundreds of sites (niche, recently released developer-tool plugin; no public active-install count in the data) — WP Query Console is a small developer-utility plugin with no published active-install count in the provided data, so the estimate assumes a niche WordPress install base and is low confidence.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.

Vendors
lubus
Products
wp query console
Ecosystems
WordPress
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news