← WordPress Vulnerabilities
WordPress security by component

Code Explorer

Code Explorer is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Feb 04, 2026; the highest CVE/CNA score is 4.9.

Plugin slug: code-explorer

CVE-2025-15487: Code Explorer: Filesystem traversal

Code Explorer is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedFeb 04, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 04, 2026 CVE-2025-15487
Code Explorer: Filesystem traversal
Code Explorer is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVDPending
Oct 30, 2024 CVE-2023-5816
Code Explorer: A security weakness
Code Explorer is affected by a security weakness. Exploitation requires at least administrator-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVD4.9