WordPress Plugin Vulnerabilities

Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via update_code_snippet

Description

The plugin does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allowing an administrator of a single subsite on a multisite network to activate, deactivate and reprioritise network-scoped snippets that run across every site in the network.

Proof of Concept

Affects Plugins

Fixed in 3.10.0

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Mohammed Abd Alrahman
Submitter
Mohammed Abd Alrahman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-07 (about 2 days ago)
Added
2026-10-07 (about 1 day ago)
Last Updated
2026-10-07 (about 1 day ago)

Other