Multiple Plugins <= Multiple Versions - Authenticated Remote Code Execution
highMultiple plugins and/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 5.4.12
- Fixed in:
- 5.4.12
- Disclosed:
- Jun 15, 2026