Junglewise Threat Intelligence

CVE-2026-56049: Post Snippets Remote Code Execution in WordPress Plugin

CVE-2026-56049 · Severity: high · CVSS 8.5 · Published 2026-06-25

Executive brief

Post Snippets is a WordPress plugin that allows users to create and manage reusable code fragments for their websites. A security flaw in versions 4.0.19 and earlier allows users with 'Contributor' level access to execute unauthorized code on the server. This could lead to a complete takeover of the website, data theft, or the installation of persistent backdoors.

Technical details

A Remote Code Execution (RCE) vulnerability exists in the Post Snippets plugin for WordPress (versions up to 4.0.19) due to improper control of code generation (CWE-94). The flaw allows an attacker with 'Contributor' or higher privileges to inject and execute arbitrary PHP code on the server. While the attack requires network access and specific user privileges, the impact is critical as it allows for full system compromise and bypasses security boundaries (Scope: Changed). The issue is resolved in version 4.1.0.

Affected products

  • Post Snippets Post Snippets <= 4.0.19

Timeline

  • 2026-04-27: other: Vulnerability reported by researcher daroo
  • 2026-06-25: disclosed: Public disclosure of CVE-2026-56049
  • 2026-06-25: patched: Patch released in version 4.1.0

References

Related threats