CVE-2025-6784
HIGHCode Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2025-6784. PoCs published by incogbyte.
AI-analyzed exploit summary This PoC exploits CVE-2025-6784, a critical vulnerability in the WordPress Code Engine plugin (≤0.3.5) allowing Contributor+ users to execute arbitrary PHP via a crafted shortcode in a draft post preview. The exploit leverages missing capability checks during shortcode rendering when PHP blocks are enabled by an admin.
Description
The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the plugin. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Exploits (1)
This PoC exploits CVE-2025-6784, a critical vulnerability in the WordPress Code Engine plugin (≤0.3.5) allowing Contributor+ users to execute arbitrary PHP via a crafted shortcode in a draft post preview. The exploit leverages missing capability checks during shortcode rendering when PHP blocks are enabled by an admin.
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H