CVE-2026-4375: Unknown Doleads Integrator

Critical severity, CVSS 9.0. EPSS: 0.4% chance of exploitation in the next 30 days.

The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.

Affected products

  • Unknown Doleads Integrator: up to and including 0.65
  • Unknown WP2EPUB: up to and including 0.65

Published 2026-07-07. Last modified 2026-07-07.