Executive brief
RepairBuddy is a WordPress plugin used for managing computer repair shop operations and customer workflows. A vulnerability in versions up to 4.1224 allows users with subscriber-level privileges to execute arbitrary code on the web server, potentially leading to full system compromise, data theft, or website defacement.
Technical details
The RepairBuddy plugin (<=4.1224) contains a remote code execution vulnerability accessible to subscribers, classified as an injection flaw. The vulnerability allows authenticated subscribers to execute arbitrary server-side commands without additional user interaction. The exact vulnerable component and injection point are not publicly disclosed in the references, but the low privilege requirement (subscriber role) and network-accessible attack vector make this particularly dangerous for multi-user WordPress installations. A patch is available in version 4.1225 and later.
Affected products
- Webful Creations RepairBuddy <=4.1224
Timeline
- 2026-09-09: disclosed
- 2026-09-10: patched: Patch released as version 4.1225