CVE-2026-25366: WordPress Woody ad snippets plugin <= 2.7.1 - Remote Code Execution (RCE) vulnerability
Published Mar 25, 2026
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.
Affected Software
1 affected component
Themeisle Woody ad snippets<=2.7.1
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25366?
CVE-2026-25366 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2026-25366?
To fix CVE-2026-25366, update the Woody ad snippets plugin to the latest version beyond 2.7.1.
3
Can CVE-2026-25366 be exploited remotely?
Yes, CVE-2026-25366 can be exploited remotely due to its nature as a remote code execution vulnerability.
4
Which versions of the Woody ad snippets plugin are affected by CVE-2026-25366?
All versions of the Woody ad snippets plugin from n/a to 2.7.1 are affected by CVE-2026-25366.
5
What can attackers achieve with CVE-2026-25366?
Attackers can execute arbitrary code on the affected WordPress site, compromising its security and functionality.