Boletines de Vulnerabilidades

CVE-2026-6433

   
Software afectado WORDPRESS
 
The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-6433