WPHizmet

Eklenti güvenlik geçmişi

WP Coder güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) WP Coder – Insert & Manage Code Snippets eklentisi için 5 açık kaydı bulunuyor; en yenisi 7 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 3 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 4.5.2.

Toplam kayıt
5
Kritik veya yüksek
3
Oturumsuz istismar
3
Son kayıt
7 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-104677Yüksek · 7,27 Ekim 2026

    uzaktan kod çalıştırma

    Etkilenen sürümler: 4.5.2 öncesi

    The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.

    Türkçe kayıt ve ne yapmalı
  • CVE-2025-24699Yüksek · 7,114 Şubat 2025

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.6 ve öncesi · Oturum açmadan istismar edilebilir

    Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company WP Coder wp-coder allows Cross-Site Scripting (XSS).This issue affects WP Coder: from n/a through <= 3.6.

  • CVE-2024-2578Orta · 4,821 Mart 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.5 ve öncesi

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5.

  • CVE-2022-2388Orta · 6,522 Ağustos 2022

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 2.5.3 öncesi · Oturum açmadan istismar edilebilir

    The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

  • CVE-2021-25053Yüksek · 8,810 Ocak 2022

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 2.5.2 öncesi · Oturum açmadan istismar edilebilir

    The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.