Junglewise Threat Intelligence

CVE-2026-45293: WordPress Coding Standards eval injection in EnqueuedResourceParameters sniff

CVE-2026-45293 · Severity: high · CVSS 8.6 · Published 2026-07-28

Vendors: Wordpress, Packagist.

Executive brief

WordPress Coding Standards is a tool used by developers and automated systems to ensure PHP code follows specific quality guidelines. A security flaw in this tool allows a specially crafted piece of code to execute commands on the computer or server performing the scan. This could lead to a full system compromise if a developer reviews untrusted third-party code or if an automated build pipeline processes a malicious contribution.

Technical details

An eval injection vulnerability exists in the `WordPress.WP.EnqueuedResourceParameters` sniff within the WordPress and WordPress-Extra rulesets. The vulnerability is located in the `is_falsy()` method, which attempts to determine if the `$ver` argument in functions like `wp_enqueue_script()` is falsy by reconstructing the argument and passing it directly to `eval()`. An attacker can exploit this by placing malicious PHP code (e.g., `'system'('id')`) within the version argument of a script enrollment function in a file being scanned. Execution occurs on the host running PHP_CodeSniffer (PHPCS). The issue is resolved in version 3.4.1 by replacing `eval()` with explicit token-level checks.

Affected products

  • WordPress WordPress-Coding-Standards (WordPressCS) >= 0.14.1, < 3.4.1

Timeline

  • 2026-07-27: patched: Fixed in version 3.4.1
  • 2026-07-27: advisory: GitHub Security Advisory GHSA-3pwp-g2mj-5p3v published
  • 2026-07-28: disclosed: CVE-2026-45293 published to NVD

References