CVE-2025-13035

T

he Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable and subsequently passed to require_once. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server via the `[code_snippet]` shortcode using PHP filter chains granted they can trick an administrator into enabling the "Enable file-based execution" setting and creating at least one active Content snippet.

Configurations

No configuration.

History

19 Nov 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 08:15

Updated : 2025-11-19 19:14


NVD link : CVE-2025-13035

Mitre link : CVE-2025-13035

CVE.ORG link : CVE-2025-13035


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')