← WordPress Vulnerabilities
WordPress security by component

Custom css-js-php

Custom css-js-php is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published May 11, 2026; the highest CVE/CNA score is 7.3.

Plugin slug: custom-css-js-php

CVE-2026-6433: Custom css-js-php: A security weakness

Custom css-js-php is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 2.0.7 through 2.0.7.

PublishedMay 11, 2026
Known safe version> 2.0.7
Safe version
May 11, 2026 CVE-2026-6433
Custom css-js-php: A security weakness
Custom css-js-php is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 2.0.7 through 2.0.7.
> 2.0.7
CVE7.3
NVDPending
Oct 20, 2023 CVE-2021-4418
Custom CSS, JS & PHP: Cross-site request forgery
Custom CSS, JS & PHP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3