Description
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The WP Coder plugin before version 4.5.2 does not enforce an administrative access check when invoking its PHP code‑execution feature. Instead, it relies on a content editing capability that is granted to editors by default. An editor‑level user can therefore save and run arbitrary PHP code on the server, resulting in a full compromise of the site, including data theft or site takeover.

Affected Systems

Installation of WP Coder versions 4.0 through 4.5.1 on any WordPress site. The flaw exists in the core plugin functionality and affects all users who possess the default editor role or any custom role containing the content editing capability.

Risk and Exploitability

The vulnerability enables attackers with editor access to execute arbitrary code; no additional exploitation steps are required. Because the code‑execution endpoint is unauthenticated to the administrator level, the attack can be carried out by any editor or user who can obtain editor credentials. Exploitation is straightforward and would not be constrained by environmental factors. No EPSS information is available and the issue is not listed in the CISA KEV catalog, but the absence of the patch indicates a high potential for exploitation in any live deployment.

Generated by OpenCVE AI on October 7, 2026 at 07:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest WP Coder release (4.5.2 or later) which restricts PHP execution to administrators
  • If an update is not possible, disable the PHP execution capability through the plugin settings or remove the plugin entirely
  • Revoke the default editor capability from roles that do not need content editing or consider implementing a least‑privilege role model

Generated by OpenCVE AI on October 7, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
CWE-284

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
Title WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:05.947Z

Reserved: 2026-10-02T08:02:37.760Z

Link: CVE-2026-104677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:58.260

Modified: 2026-10-07T07:16:58.260

Link: CVE-2026-104677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:00:12Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions

  • CWE-284

    Improper Access Control