CVE-2026-73992: WordPress Query Wrangler plugin <= 1.5.57 - Remote Code Execution (RCE) vulnerability
Published Aug 20, 2026
·Updated
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Affected Software
1 affected component
WordPress Query Wrangler plugin<=1.5.57
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Query Wrangler pluginto a version that resolves this vulnerability.Fixed in 1.5.58
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Subscriber-level access to a WordPress site running Query Wrangler version 1.5.57 or earlier. No user interaction is required.
2
What is the potential impact of successful exploitation?
Successful exploitation can result in remote code execution. The listed impact includes high confidentiality, integrity, and availability impact, and the scope may extend beyond the vulnerable component.
3
Which installations should be treated as affected?
Sites using the Query Wrangler WordPress plugin at version 1.5.57 or earlier should be treated as affected based on the provided information.