Junglewise Threat Intelligence

CVE-2026-57766: XplodedThemes WPIDE CSRF in File Manager and Code Editor

CVE-2026-57766 · Severity: high · CVSS 8.8 · Published 2026-07-02

Executive brief

WPIDE is a WordPress plugin used by site administrators to manage files and edit code directly from the dashboard. A security flaw allows an attacker to trick a logged-in administrator into performing unintended actions, such as modifying site files or changing configurations, by clicking a malicious link. This could lead to a full takeover of the website or the injection of malicious code.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WPIDE – File Manager & Code Editor plugin for WordPress (versions 3.5.6 and below) due to insufficient nonce validation or state-changing request protections. An unauthenticated remote attacker can craft a malicious web page or link that, when visited by a logged-in administrator, triggers sensitive actions within the plugin's file management or code editing features. Successful exploitation could allow the attacker to modify, delete, or upload files, potentially leading to Remote Code Execution (RCE). As of the advisory date, no official patch has been released.

Affected products

  • XplodedThemes WPIDE – File Manager & Code Editor <= 3.5.6

Timeline

  • 2026-05-02: disclosed: Reported by dodoh4t
  • 2026-07-02: advisory: Published by Patchstack and NVD

References