plugin

Allow Php In Posts And Pages Vulnerabilities

1 known security issue reported for the Allow Php In Posts And Pages WordPress plugin. Most recent disclosed Sep 15, 2023.

1 critical

Running Allow Php In Posts And Pages on your site? Check whether your installed version is affected.

Scan your site free

Allow PHP in Posts and Pages <= 3.0.4 - Authenticated (Subscriber+) Remote Code Execution via Shortcode

critical

The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.

CVSS:
9.9
Affected:
up to 3.0.4
Fix:
No patched version reported
Disclosed:
Sep 15, 2023

CVE-2023-4994 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database