CVE-2026-65553
Received Received - Intake

Unauthenticated RCE in Spider Analyser WordPress Plugin

Vulnerability report for CVE-2026-65553, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: Patchstack

Description

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
spider_analyser wordpress_search_engine_spider_analysis_plugin 2.1.3
patchstack spider_analyser to 2.1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-65553 is an unauthenticated Remote Code Execution (RCE) vulnerability in the WordPress Spider Analyser plugin versions 2.1.3 and below. It allows attackers to execute arbitrary commands on the server without authentication, potentially gaining full control of the affected website.

Detection Guidance

Check if the Spider Analyser WordPress plugin version 2.1.3 or below is installed. Look for suspicious activity like unexpected command execution or unauthorized access attempts.

Impact Analysis

This vulnerability can lead to complete website compromise, data theft, defacement, or use of the server for malicious activities like hosting malware or launching attacks on other systems. Attackers can exploit it remotely without any user interaction.

Compliance Impact

This RCE vulnerability can result in unauthorized access to sensitive data, violating compliance requirements such as GDPR and HIPAA. Organizations may face legal penalties, data breach notifications, and reputational damage due to compromised personal or health information.

Mitigation Strategies

Disable the Spider Analyser plugin immediately. Apply Patchstack's mitigation rule if available. Contact your hosting provider or developer for further assistance until an official patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65553. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart