Executive brief
Post Snippets is a WordPress plugin that allows users to create and manage reusable code fragments for their websites. A security flaw in versions 4.0.19 and earlier allows users with 'Contributor' level access to execute unauthorized code on the server. This could lead to a complete takeover of the website, data theft, or the installation of persistent backdoors.
Technical details
A Remote Code Execution (RCE) vulnerability exists in the Post Snippets plugin for WordPress (versions up to 4.0.19) due to improper control of code generation (CWE-94). The flaw allows an attacker with 'Contributor' or higher privileges to inject and execute arbitrary PHP code on the server. While the attack requires network access and specific user privileges, the impact is critical as it allows for full system compromise and bypasses security boundaries (Scope: Changed). The issue is resolved in version 4.1.0.
Affected products
- Post Snippets Post Snippets <= 4.0.19
Timeline
- 2026-04-27: other: Vulnerability reported by researcher daroo
- 2026-06-25: disclosed: Public disclosure of CVE-2026-56049
- 2026-06-25: patched: Patch released in version 4.1.0