Ghostwire

CVE-2026-6433: The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL...

UNKNOWN CVSS 0.0

Published: May 11, 2026 | Last Modified: May 11, 2026

Description

The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References