Custom css-js-php <= 2.0.7 - Unauthenticated Remote Code Execution
critical
The Custom css-js-php plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.7. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 2.0.7
- Fix:
- No patched version reported
- Disclosed:
- May 12, 2026
CVE-2026-6433 on NVD →
Custom CSS, JS & PHP <= 2.0.7 - Cross-Site Request Forgery Bypass
medium
The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save code snippets via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 2.0.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 8, 2021
CVE-2021-4418 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database