CVE-2026-104677
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 07, 2026
Vendor
unknown
Description
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.