THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14498 (HIGH 8.8) — The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with uns

[NVD] CVE-2026-14498 (HIGH 8.8) — The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with uns

mednvdPublished 2026-08-16

CVE-2026-14498 CVSS: 8.8 HIGH Published: 2026-08-16T05:16:46.360

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing s

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14498