CVE-2025-13035
The Code Snippets plugin for WordPress is vulnerable to a PHP code injection attack, affecting all versions up to and including 3.9.1. An attacker with Contributor-level access or higher can exploit this vulnerability by manipulating shortcode attributes to overwrite a variable that is then used to load arbitrary PHP code. This requires the attacker to trick an administrator into enabling a specific plugin setting and creating at least one active content snippet. Once these conditions are met, the attacker can execute arbitrary PHP code on the server.
Based on public CVE data (MITRE/NVD).