ZeroHour

CVE-2026-81803

niche

Subscriber-level RCE in WordPress RepairBuddy plugin (versions <= 4.1224)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81803 is a code injection vulnerability (CWE-94) in the RepairBuddy WordPress plugin that allows a user holding the lowest WordPress role, Subscriber, to achieve remote code execution on the affected site. It is triggered by an authenticated request sent from a subscriber-level account to a vulnerable plugin component; the high attack complexity score (AC:H) indicates that some additional, site-dependent condition must also line up for the injection to succeed. A successful attacker gains arbitrary code execution on the web server, with high impact to confidentiality, integrity, and availability, which can lead to full site compromise. Any WordPress site running RepairBuddy version 4.1224 or earlier is affected, and on sites with open user registration an attacker can self-register as a subscriber to meet the low privilege requirement. No public proof of concept, CISA KEV listing, or reports of in-the-wild exploitation are currently known.

What to do: Upgrade RepairBuddy to the newest version published by the vendor (any release above 4.1224), and until patched, consider deactivating the plugin since only subscriber-level privileges are required and many sites allow self-registration. Restrict or disable open user registration and audit existing subscriber accounts for unexpected sign-ups. Monitor the Patchstack advisory and CVE record for the confirmed fixed version and any published proof of concept.

Affected
RepairBuddy (WordPress plugin)<= 4.1224
Estimated exposure
niche≈ a few thousand sites (order of 10^3; small WordPress.org install base) — RepairBuddy is a niche repair-shop management plugin whose WordPress.org active-install count is on the order of only a few thousand, so exposure is plausibly limited to a few thousand sites, most of them small repair businesses.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

Ecosystems
WordPress
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.