CVE-2008-1059

NUCLEI

Wordpress Sniplets Plugin - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NBBN · textwebappsphp
https://www.exploit-db.com/exploits/5194

Nuclei Templates (1)

WordPress Sniplets 1.1.2 - Local File Inclusion
HIGHby dhiyaneshDK

Scores

EPSS 0.0019
EPSS Percentile 41.3%

Details

CWE
CWE-94
Status published
Products (2)
wordpress/sniplets_plugin 1.1.2
wordpress/sniplets_plugin 1.2.2
Published Feb 28, 2008
Tracked Since Feb 18, 2026