Vulnerabilities / QA Assistants – Driven by data / WPSEC-2026-0565
QA Assistants – Driven by data <= 5.3.0.0 - Unauthenticated Path Traversal to Limited File Overwrite via 'readers_name' and 'raw_name' Parameters
Critical 9.1
CWE-22Fixed in 5.3.0.1
- ID
- WPSEC-2026-0565
- Plugin
- QA Assistants – Driven by data (qa-heatmap-analytics)
- Affected
- all versions before 5.3.0.1
- Remediation
- Update to 5.3.0.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Weakness
- CWE-22
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- QA Assistants – Driven by data on WPSec AttackSurface
- Fix released
- Published
Description
The QA Assistants – Driven by data plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.3.0.0. This is due to the public tracking endpoint building file paths from client-supplied values without validation. This makes it possible for unauthenticated attackers to overwrite existing PHP files that the web server can write to with plugin session data, which can take the site offline, and to create files outside the plugin's data directory. The written data is not executed as code.
References
- https://wpsec.com/vuln/WPSEC-2026-0565/
- https://plugins.svn.wordpress.org/qa-heatmap-analytics/tags/5.3.0.1/
- https://wordpress.org/plugins/qa-heatmap-analytics/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS