CVE-2026-6433: Unknown Custom Css-Js-PHP

High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.

The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.

Affected products

  • Unknown Custom Css-Js-PHP: from 2.0.7, up to and including 2.0.7

Published 2026-05-11. Last modified 2026-06-17.