CVE-2026-104677 PUBLISHED

WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP

Assigner: WPScan
Reserved: 02.10.2026 Published: 07.10.2026 Updated: 07.10.2026

The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.

Product Status

Vendor Unknown
Product WP Coder
Versions Default: unaffected
  • affected from 4.0 to 4.5.2 (excl.)

Credits

  • Ayush Srivastava finder
  • WPScan coordinator

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE