he Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable and subsequently passed to require_once. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server via the `[code_snippet]` shortcode using PHP filter chains granted they can trick an administrator into enabling the "Enable file-based execution" setting and creating at least one active Content snippet.
No configuration.
19 Nov 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-11-19 08:15
Updated : 2025-11-19 19:14
NVD link : CVE-2025-13035
Mitre link : CVE-2025-13035
CVE.ORG link : CVE-2025-13035
JSON object : View
No product.
Improper Control of Generation of Code ('Code Injection')