Description
The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download and update actions in the Cloud_Search_List_Table class. This makes it possible for unauthenticated attackers to force logged-in administrators to download or update cloud snippets without their consent via a crafted request, granted they can trick an administrator into visiting a malicious page.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
* (semver)
Timeline
| 2026-02-02: | Vendor Notified |
| 2026-02-05: | Disclosed |
Credits
M Indra Purnama
References
www.wordfence.com/...-6a16-491a-aa01-6222f275cf0f?source=cve
plugins.trac.wordpress.org/...ss-cloud-search-list-table.php
plugins.trac.wordpress.org/...ss-cloud-search-list-table.php
plugins.trac.wordpress.org/...loud/list-table-shared-ops.php
plugins.trac.wordpress.org/...loud/list-table-shared-ops.php
github.com/codesnippetspro/code-snippets/pull/331/changes