What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion.This issue affects Advanced Woo Labels: from n/a through <= 2.36.
Explanation of Vulnerability in Simple Terms
02Summary
Advanced Woo Labels versions 2.36 and earlier contain a code injection vulnerability that allows high-privilege users to execute arbitrary PHP code on the site. An attacker with admin or equivalent access can inject malicious code through the plugin's input handling. This affects confidentiality, integrity, and availability of the site.
What an attacker can do
03Attacker Capabilities
Run arbitrary PHP code on the site with full site privileges.
Potential impact on your site
04Site Impact
A compromised admin account can execute code to steal data, modify content, or disable the site entirely.
Conditions required to exploit
05Prerequisites
Attacker must have high-level admin or equivalent privileges on the WordPress site.
Key dates
06Disclosure timeline
March 13, 2026
CVE published
April 29, 2026
Record updated