๐Ÿ” CVE Alert

CVE-2026-106095

UNKNOWN 0.0

Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via update_code_snippet

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Code Snippets WordPress plugin before 3.10.0 does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allowing an administrator of a single subsite on a multisite network to activate, deactivate and reprioritise network-scoped snippets that run across every site in the network.

Vendor unknown
Product code snippets
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown code snippets

Be the first to know when new unknown vulnerabilities affecting unknown code snippets are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Code Snippets
0 < 3.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4aeddbb6-d7a9-48cb-96ea-5898586bce04/

Credits

Mohammed Abd Alrahman WPScan