CVE-2023-4994
CRITICAL EXPLOITEDAllow PHP in Posts and Pages <= 3.0.4 - Authenticated Remote Code Execution via PHP Shortcode
Title source: llmExploitation Summary
CVE-2023-4994 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.
References (2)
Core 2
Scores
CVSS v3
9.9
EPSS
0.0075
EPSS Percentile
50.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2023-09-15
CWE
CWE-94
Status
published
Products (2)
hit-reach/Allow PHP in Posts and Pages
< 3.0.4
hitreach/allow_php_in_posts_and_pages
< 3.0.4
Published
Sep 16, 2023
Tracked Since
Feb 18, 2026