The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-276 CWE-284 |
Wed, 07 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site. | |
| Title | WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-07T06:00:05.947Z
Reserved: 2026-10-02T08:02:37.760Z
Link: CVE-2026-104677
No data.
Status : Received
Published: 2026-10-07T07:16:58.260
Modified: 2026-10-07T07:16:58.260
Link: CVE-2026-104677
No data.
OpenCVE Enrichment
Updated: 2026-10-07T08:00:12Z