Junglewise Threat Intelligence

CVE-2026-73992: Query Wrangler remote code execution for subscribers

CVE-2026-73992 · Severity: critical · CVSS 9.9 · Published 2026-08-20

Executive brief

Query Wrangler is a WordPress plugin used to manage and query database content. A flaw in versions up to 1.5.57 allows subscriber-level users to execute arbitrary code on the server, potentially compromising the entire website and any data stored on it. This poses an immediate threat to any WordPress site using the vulnerable plugin, even if subscribers are restricted to low-privilege accounts.

Technical details

The vulnerability is a remote code execution flaw classified as an injection attack (OWASP A3) that allows attackers with subscriber-level privileges to execute arbitrary commands on the server. The attack requires authentication as a subscriber user but no additional user interaction or elevated privileges. Affected versions are Query Wrangler 1.5.57 and earlier; the vulnerability is patched in version 1.5.58. The high CVSS score of 9.9 reflects the severity of unauthenticated or low-privilege code execution impact on the affected system.

Affected products

  • Daggerhart Query Wrangler <=1.5.57

Timeline

  • 2026-08-20: disclosed
  • 2026-08-19: patched: Version 1.5.58 available as of 2026-08-19
  • 2026-04-30: other: Vulnerability reported

References