Beveiligingsadvies

CVE-2026-6433

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-11 06:00:01
Laatst bijgewerkt 2026-05-11 16:25:31
Toegewezen door WPScan
CVSS-score 7.3
Status PUBLISHED

Beschrijving

The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.