nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-4994 CVE-2023-4994
CRITICAL
Allow PHP in Posts and Pages <= 3.0.4 - Authenticated (Subscriber+) Remote Code Execution via Shortcode
Record summary
CVE-2023-4994 has a selected CVSS score of 9.9 (critical).
Description
The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 15, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Allow PHP in Posts and PagesBrowse hit-reach / Allow PHP in Posts and PagesDefault status: unaffected | CVE List, VulnCheck | Through 3.0.4 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/allow-php-in-posts-and-pages/trunk/allowphp.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/3d8b4bb6-3715-40c1-8140-7fcf874ccec3?source=cve