Sceawere

Vulnerability Detail

CVE-2026-65553UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Spider Analyser Unauthenticated RCE Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
1d ago
Vendor
wbolt.com
Product
Spider Analyser – WordPress搜索引擎蜘蛛分析插件
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-06T15:17:17.557Z",
  "pubdate": "2026-08-06T15:17:17.557Z",
  "executiveSummary": "An unauthenticated Remote Code Execution (RCE) vulnerability has been identified in the Spider Analyser WordPress plugin, specifically affecting versions 2.1.3 and prior. This security flaw enables remote, unauthenticated threat actors to execute arbitrary system commands on the underlying hosting server running the vulnerable WordPress installation. The vulnerability stems from improper input validation and insecure handling of user-supplied data within the plugin codebase. Successful exploitation grants attackers complete system compromise, unauthorized access to the database, modification or deletion of website content, and the potential to pivot further into the internal network hosting the infrastructure. The risk implication is critical, as no administrative privileges or prior authentication are required to trigger the exploit, significantly lowering the barrier to entry for malicious actors scanning the internet for vulnerable targets. Remediation requires immediate updates to a patched version or complete removal of the affected plugin until a secure release is deployed by the vendor.",
  "technicalDetails": "The vulnerability resides in the Spider Analyser WordPress search engine spider analysis plugin for versions <= 2.1.3. The root cause of the flaw is insecure deserialization, inadequate sanitization, or unsafe evaluation of HTTP requests handled by the plugin's exposed endpoints. Because the vulnerable component fails to properly validate and restrict input parameters before passing them to system execution functions or template engines, an external attacker can craft malicious HTTP requests containing arbitrary payloads.\nThe attack flow begins with network reconnaissance where an unauthenticated attacker identifies a target running the vulnerable Spider Analyser plugin. The attacker then constructs a specially crafted HTTP request targeted at the vulnerable script, parameter, or AJAX endpoint associated with the plugin. Upon receipt, the plugin processes the malicious input without enforcing authentication or authorization checks. The lack of proper input sanitization allows the payload to reach sensitive backend execution sinks, such as system command evaluation functions.\nExecution of the payload results in arbitrary code execution within the security context of the web server process, typically the www-data or apache user. Depending on the server configuration and local privilege escalation vectors, this can lead to full system takeover. Post-exploitation activities include the deployment of web shells, installation of persistent backdoors, data exfiltration, and lateral movement across the hosting environment. The network exposure is total, as the plugin endpoints are publicly accessible over HTTP/HTTPS protocols."
}
CVE-2026-65553: Spider Analyser Unauthenticated RCE Vulnerability (CRITICAL Severity, CVSS: 10.0) - Sceawere