CVE-2024-13890
Allow PHP Execute <= 1.0 - Authenticated (Editor+) PHP Code Injection
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP code to be entered by all users for whom unfiltered HTML is allowed. This makes it possible for authenticated attackers, with Editor-level access and above, to inject PHP code into posts and pages.
| CWE | CWE-94 |
| Vendor | sksdev |
| Product | allow php execute |
| Published | Mar 8, 2025 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for sksdev allow php execute
Be the first to know when new high vulnerabilities affecting sksdev allow php execute are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
sksdev / Allow PHP Execute
0 โค 1.0
References
Credits
Francesco Carlucci