Eklenti güvenlik geçmişi
WP Coder güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) WP Coder – Insert & Manage Code Snippets eklentisi için 5 açık kaydı bulunuyor; en yenisi 7 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 3 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 4.5.2.
- Toplam kayıt
- 5
- Kritik veya yüksek
- 3
- Oturumsuz istismar
- 3
- Son kayıt
- 7 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
uzaktan kod çalıştırma
Etkilenen sürümler: 4.5.2 öncesi
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
Türkçe kayıt ve ne yapmalısiteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.6 ve öncesi · Oturum açmadan istismar edilebilir
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company WP Coder wp-coder allows Cross-Site Scripting (XSS).This issue affects WP Coder: from n/a through <= 3.6.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.5 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 2.5.3 öncesi · Oturum açmadan istismar edilebilir
The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 2.5.2 öncesi · Oturum açmadan istismar edilebilir
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.