Skip to main content
HIGH

CVE-2026-14498

CVSS v3

8.8

HIGH

EPSS Score

1.0 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_array() guarded only by function_exists(). This makes it possible for authenticated attackers, with sub

Technical details

Published
2026-08-16
Last Modified
2026-08-16

Frequently asked questions

What is CVE-2026-14498?

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_array() guarded only by function_exists(). This makes it possible for authenticated attackers, with sub

Is CVE-2026-14498 actively exploited?

Active exploitation of CVE-2026-14498 has not been confirmed. Its EPSS score was 1.0% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-14498?

CVE-2026-14498 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2026-14498 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key