Junglewise Threat Intelligence

CVE-2026-81803: RepairBuddy Remote Code Execution in Subscriber function

CVE-2026-81803 · Severity: high · CVSS 7.5 · Published 2026-09-10

Technologies: Webful Creations RepairBuddy. Vendors: Webful Creations.

Executive brief

RepairBuddy is a WordPress plugin used for managing computer repair shop operations and customer workflows. A vulnerability in versions up to 4.1224 allows users with subscriber-level privileges to execute arbitrary code on the web server, potentially leading to full system compromise, data theft, or website defacement.

Technical details

The RepairBuddy plugin (<=4.1224) contains a remote code execution vulnerability accessible to subscribers, classified as an injection flaw. The vulnerability allows authenticated subscribers to execute arbitrary server-side commands without additional user interaction. The exact vulnerable component and injection point are not publicly disclosed in the references, but the low privilege requirement (subscriber role) and network-accessible attack vector make this particularly dangerous for multi-user WordPress installations. A patch is available in version 4.1225 and later.

Affected products

  • Webful Creations RepairBuddy <=4.1224

Timeline

  • 2026-09-09: disclosed
  • 2026-09-10: patched: Patch released as version 4.1225

References

Related threats