What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.
Explanation of Vulnerability in Simple Terms
Qode Essential Addons versions up to 1.5.2 contain a code injection vulnerability that allows authenticated users with low privileges to run arbitrary PHP code on the site. The vulnerability affects the entire system due to scope change. An attacker needs only a low-privilege account and network access to exploit it.
What an attacker can do
Run arbitrary PHP code on the site with full system access.
Potential impact on your site
Complete site compromise: data theft, malware injection, or total takeover possible.
Conditions required to exploit
Low-privilege user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities