VYPR
Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026

Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution

CVE-2025-6784

Description

The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the plugin. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.