CVE Database /
CVE-2026-8832
CVE · High
CVE-2026-8832 — WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.3.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-8832
|
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.3.6 |
Improper Control of Generation of Code ('Code Injection') |
High
8.8
|
< 2.3.6
|
2.3.6 |
2026-05-26 |
—
|
CVE-2026-8832
A vulnerability exists in WordPress plugins up to version 2.3.5 that permits unauthorized code execution. This flaw arises from the registration of a custom post type without adequate capability controls, allowing attackers with author-level access or higher to create and publish malicious PHP snippets via XML-RPC. These snippets are then executed by the server when rendered through a specific shortcode.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings