← WordPress Vulnerabilities
WordPress security by component

Allow PHP in Posts and Pages

Allow PHP in Posts and Pages is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 16, 2023; the highest CVE/CNA score is 9.9.

Plugin slug: allow-php-in-posts-and-pages

CVE-2023-4994: Allow PHP in Posts and Pages: Code execution

Allow PHP in Posts and Pages is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.

PublishedSep 16, 2023
Safe version guidanceSee mitigation notes
Safe version
Sep 16, 2023 CVE-2023-4994
Allow PHP in Posts and Pages: Code execution
Allow PHP in Posts and Pages is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.9
NVD6.4