CVE-2026-106095: Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via update_code_snippet
The Code Snippets WordPress plugin before 3.10.0 does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allowing an administrator of a single subsite on a multisite network to activate, deactivate and reprioritise network-scoped snippets that run across every site in the network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Code Snippets WordPress pluginto a version that resolves this vulnerability.Fixed in 3.10.0
Event History
Frequently Asked Questions
Who can exploit this issue in a multisite deployment?
An administrator of a single subsite can exploit it. The issue lets that user manage network-scoped snippets even though those snippets run across every site in the network.
What actions can an attacker perform against network-scoped snippets?
They can activate, deactivate, and change the priority of targeted network-scoped snippets through the affected snippet-management action.
Are non-multisite WordPress installations affected in the same way?
The described impact depends on a multisite network and on the distinction between a subsite administrator and network-scoped snippets. The provided information does not establish the same cross-site impact for a non-multisite installation.
What version addresses the issue?
Code Snippets versions before 3.10.0 are affected. Updating to version 3.10.0 or later addresses the stated vulnerable version range.