CVE-2025-48169: WordPress Code Engine Plugin <= 0.3.3 - Remote Code Execution (RCE) Vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine allows Remote Code Inclusion. This issue affects Code Engine: from n/a through 0.3.3.
Other sources
Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Remote Code Inclusion.This issue affects Code Engine: from n/a through <= 0.3.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48169?
CVE-2025-48169 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-48169?
To fix CVE-2025-48169, update the Jordy Meow Code Engine and WordPress Code Engine Plugin to the latest version beyond 0.3.3.
What type of vulnerability is CVE-2025-48169?
CVE-2025-48169 is an improper control of code generation vulnerability, allowing for remote code inclusion.
Which software versions are affected by CVE-2025-48169?
CVE-2025-48169 affects Jordy Meow Code Engine and WordPress Code Engine Plugin versions up to and including 0.3.3.
Can CVE-2025-48169 be exploited remotely?
Yes, CVE-2025-48169 can be exploited remotely, making it critical to address immediately.