Impact
The WP Coder plugin before version 4.5.2 does not enforce an administrative access check when invoking its PHP code‑execution feature. Instead, it relies on a content editing capability that is granted to editors by default. An editor‑level user can therefore save and run arbitrary PHP code on the server, resulting in a full compromise of the site, including data theft or site takeover.
Affected Systems
Installation of WP Coder versions 4.0 through 4.5.1 on any WordPress site. The flaw exists in the core plugin functionality and affects all users who possess the default editor role or any custom role containing the content editing capability.
Risk and Exploitability
The vulnerability enables attackers with editor access to execute arbitrary code; no additional exploitation steps are required. Because the code‑execution endpoint is unauthenticated to the administrator level, the attack can be carried out by any editor or user who can obtain editor credentials. Exploitation is straightforward and would not be constrained by environmental factors. No EPSS information is available and the issue is not listed in the CISA KEV catalog, but the absence of the patch indicates a high potential for exploitation in any live deployment.
OpenCVE Enrichment