What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.
Explanation of Vulnerability in Simple Terms
Customify Site Library versions 0.0.9 and earlier allow authenticated users to inject and execute arbitrary code on the site. An attacker with low-level access can run their own PHP code, potentially compromising the entire WordPress installation. The vulnerability affects all confidentiality, integrity, and availability of the site.
What an attacker can do
Run arbitrary PHP code on the site and take full control of it.
Potential impact on your site
Complete site compromise: data theft, malware injection, defacement, or total loss of availability.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities