HomeDefault status
unknown
2.0.7 (semver)
affected
Description
The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
2.0.7 (semver)
Credits
John Umoru
WPScan
References
wpscan.com/...rability/a0b1c059-e156-4402-ac8d-67f8ad7386cc/