Executive brief
The DoLeads Integrator and wp2epub WordPress plugins contain a critical security flaw that allows unauthorized individuals to execute arbitrary code on a website. This vulnerability can be exploited if these plugins are installed on a blog, potentially through other weaknesses that allow unauthorized plugin installation. An attacker could use this to take full control of the website, steal sensitive data, or disrupt operations.
Technical details
The DoLeads Integrator (up to 1.2.2) and wp2epub (up to 0.65) plugins for WordPress are susceptible to unauthenticated Remote Code Execution (RCE). The vulnerability is categorized as code injection (CWE-94) and has been observed being used in conjunction with other flaws that allow unauthorized users to install unclosed extensions from the WordPress repository. Once the plugins are present on a site, an attacker can execute arbitrary PHP code without any prior authentication. There is currently no known fix or patch available for these plugins.
Affected products
- Unknown DoLeads Integrator <= 1.2.2
- Unknown wp2epub <= 0.65
Timeline
- 2026-06-16: disclosed: Publicly published by WPScan
- 2026-07-07: advisory: NVD publication date