CVE-2026-104677: Unknown Wp Coder

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.

Affected products

  • Unknown Wp Coder: from 4.0, before 4.5.2 (fixed in 4.5.2)

Published 2026-10-07. Last modified 2026-10-07.