CVE-2026-6433

CVE-2026-6433: Custom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCE

Vendor Unknown
Product Custom css-js-php
Published May 11, 2026
Last update May 11, 2026

CVSS base score

What the vulnerability does

01Description

The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.

Explanation of Vulnerability in Simple Terms

02Summary

A vulnerability exists in Custom css-js-php version 2.0.7. Due to missing security metadata, the specific attack vector and impact cannot be determined from available information. Site administrators should contact the vendor for details and apply updates when available.

What an attacker can do

03Attacker Capabilities

Unknown; insufficient technical data provided.

Potential impact on your site

04Site Impact

Unknown impact; vendor and patch status unclear.

Conditions required to exploit

05Prerequisites

Unknown; insufficient technical data provided.

Key dates

06Disclosure timeline

May 11, 2026 CVE published
May 11, 2026 Record updated