A critical security vulnerability (CVE-2026-65553) has been disclosed in the Spider Analyser WordPress plugin, affecting all versions up to 2.1.3. The flaw enables unauthenticated attackers to execute arbitrary code remotely without requiring user interaction or authentication credentials. This vulnerability carries a CVSS score of 10.0, indicating the highest possible severity. WordPress sites utilizing the Spider Analyser plugin within the affected version range are at immediate risk of compromise. Successful exploitation could allow attackers to gain full control over vulnerable systems, potentially leading to data exfiltration, service disruption, or further lateral movement within networks. Site administrators are strongly advised to update to the latest patched version of the plugin immediately. For environments where updates are not yet available, temporary mitigation measures include restricting plugin access to trusted IP ranges and monitoring server logs for suspicious activity. This vulnerability underscores the importance of maintaining up-to-date software dependencies in content management systems.
CRITICAL
CVSS 10.0
CVE-2026-65553
2026-08-17
Critical RCE Vulnerability in WordPress Spider Analyser Plugin (CVE-2026-65553)
A critical unauthenticated remote code execution vulnerability (CVE-2026-65553) affects Spider Analyser WordPress plugin versions ≤2.1.3. Immediate patching is required to mitigate severe exploitation risks.