CVE-2025-6784

The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the plugin. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-11 07:16

Updated : 2026-07-13 16:59


NVD link : CVE-2025-6784

Mitre link : CVE-2025-6784

CVE.ORG link : CVE-2025-6784


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')