WordPress Plugin Vulnerabilities
Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via update_code_snippet
Description
The plugin does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allowing an administrator of a single subsite on a multisite network to activate, deactivate and reprioritise network-scoped snippets that run across every site in the network.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Mohammed Abd Alrahman
Submitter
Mohammed Abd Alrahman
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-07 (about 2 days ago)
Added
2026-10-07 (about 1 day ago)
Last Updated
2026-10-07 (about 1 day ago)