CVE-2026-6433: Unknown Custom Css-Js-PHP
High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.
The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.
Affected products
- Unknown Custom Css-Js-PHP: from 2.0.7, up to and including 2.0.7
Published 2026-05-11. Last modified 2026-06-17.