CVE-2026-104677: WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Coderto a version that resolves this vulnerability.Fixed in 4.5.2
Event History
Frequently Asked Questions
Who can exploit this issue in a typical WordPress installation?
An authenticated user with the Editor role can exploit it, because Editors hold the content capability used by the plugin's insufficient access check by default. The attacker does not need administrator privileges or user interaction.
What access does successful exploitation provide?
An Editor-level attacker can save and execute arbitrary PHP code on the server. This can result in full compromise of the WordPress site, including confidentiality, integrity, and availability impacts.
Which WP Coder versions are affected?
WP Coder versions before 4.5.2 are affected. Updating to version 4.5.2 or later addresses the vulnerable access control behavior.