What is CVE-2026-14498?
The Query Wrangler plugin for WordPress (versions up to 1.5.57) is vulnerable to Remote Code Execution via the 'options' parameter. This is due to missing capability checks and nonce verification on the wp_ajax_qw_form_ajax handler. Immediate update to the latest version is recommended.
Azərbaycanca: WordPress-in Query Wrangler plaqini (1.5.57 və əvvəlki versiyalar) `options` parametri vasitəsilə Remote Code Execution zəifliyinə məruz qalır. Bu, `wp_ajax_qw_form_ajax` handler-də capability check və nonce doğrulamasının olmaması səbəbindən baş verir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which WordPress plugin is affected by CVE-2026-14498?
The Query Wrangler plugin, versions up to 1.5.57, is affected.
What type of vulnerability is this and how is it exploited?
It is a Remote Code Execution (RCE) vulnerability, exploited via the 'options' parameter due to missing capability checks and nonce verification on the wp_ajax_qw_form_ajax handler.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.