← Back

CVE-2023-4994

nvd nist
Published: Sep 16, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Exploitability: 3.1 / Impact: 2.7
Source: NVD

Description

The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.

Affected (1)

1 product
Allow Php In Posts And Pages
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.0.4

Timeline

No history available yet.