Executive brief
WordPress Coding Standards is a tool used by developers and automated systems to ensure PHP code follows specific quality guidelines. A security flaw in this tool allows a specially crafted piece of code to execute commands on the computer or server performing the scan. This could lead to a full system compromise if a developer reviews untrusted third-party code or if an automated build pipeline processes a malicious contribution.
Technical details
An eval injection vulnerability exists in the `WordPress.WP.EnqueuedResourceParameters` sniff within the WordPress and WordPress-Extra rulesets. The vulnerability is located in the `is_falsy()` method, which attempts to determine if the `$ver` argument in functions like `wp_enqueue_script()` is falsy by reconstructing the argument and passing it directly to `eval()`. An attacker can exploit this by placing malicious PHP code (e.g., `'system'('id')`) within the version argument of a script enrollment function in a file being scanned. Execution occurs on the host running PHP_CodeSniffer (PHPCS). The issue is resolved in version 3.4.1 by replacing `eval()` with explicit token-level checks.
Affected products
- WordPress WordPress-Coding-Standards (WordPressCS) >= 0.14.1, < 3.4.1
Timeline
- 2026-07-27: patched: Fixed in version 3.4.1
- 2026-07-27: advisory: GitHub Security Advisory GHSA-3pwp-g2mj-5p3v published
- 2026-07-28: disclosed: CVE-2026-45293 published to NVD
References
- https://github.com/WordPress/WordPress-Coding-Standards/commit/a29048d0bbef5cf25d42349c74e4072d3cbc8325
- https://github.com/WordPress/WordPress-Coding-Standards/pull/2771
- https://github.com/WordPress/WordPress-Coding-Standards/releases/tag/3.4.1
- https://github.com/WordPress/WordPress-Coding-Standards/security/advisories/GHSA-3pwp-g2mj-5p3v