CVE-2026-104677: Unknown Wp Coder
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
Affected products
- Unknown Wp Coder: from 4.0, before 4.5.2 (fixed in 4.5.2)
Published 2026-10-07. Last modified 2026-10-07.