Description
The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin allowing Author-level users to create and execute arbitrary PHP code through the Code Snippets feature without proper capability checks. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server, leading to remote code execution, privilege escalation, and complete site compromise.
Published: 2025-12-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in the WPMasterToolKit plugin allows authenticated users with Contributor-level access to inject and execute arbitrary PHP code through the Code Snippets feature. This code injection is a weakness that can lead to remote code execution, privilege escalation to higher WordPress roles, and eventual full site compromise. The weakness is categorized as CWE‑94, indicating an injection of malicious code without proper validation or sanitization.

Affected Systems

All releases of the WPMasterToolKit (WPMTK) WordPress plugin up to version 2.13.0 are affected. The issue exists in the core module handling code snippets and is present in the plugin files historical and trunk versions referenced in the advisory. No other products or vendors are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 places the vulnerability in the medium severity range, and the EPSS score of less than 1% suggests a low yet non‑zero probability of exploitation. When combined with the fact that the attack vector requires an authenticated Contributor or higher, the risk is mitigated by the need for user access but remains significant if such users exist on the site. The vulnerability is not listed in the CISA KEV catalog, further indicating that actively exploited instances are not currently documented. An attacker would exploit the plugin's lack of capability checks by submitting malicious PHP through the user interface and then executing it via the same interface, allowing code execution on the server.

Generated by OpenCVE AI on April 21, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPMasterToolKit to the latest version that addresses the code injection flaw.
  • If an immediate upgrade is not possible, disable or remove the Code Snippets feature until the fix is available.
  • Restrict Contributor-level access and monitor the site for any unauthorized code execution attempts.

Generated by OpenCVE AI on April 21, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 15 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 12 Dec 2025 03:45:00 +0000

Type Values Removed Values Added
Description The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin allowing Author-level users to create and execute arbitrary PHP code through the Code Snippets feature without proper capability checks. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server, leading to remote code execution, privilege escalation, and complete site compromise.
Title WPMasterToolKit (WPMTK) <= 2.13.0 - Authenticated (Contributor+) Code Injection
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:56:35.965Z

Reserved: 2025-12-05T21:21:47.576Z

Link: CVE-2025-14166

cve-icon Vulnrichment

Updated: 2025-12-15T17:54:34.924Z

cve-icon NVD

Status : Deferred

Published: 2025-12-12T04:15:49.257

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T17:30:37Z

Weaknesses