What the vulnerability does
01Description
The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.
Explanation of Vulnerability in Simple Terms
02Summary
A vulnerability exists in Custom css-js-php version 2.0.7. Due to missing security metadata, the specific attack vector and impact cannot be determined from available information. Site administrators should contact the vendor for details and apply updates when available.
What an attacker can do
03Attacker Capabilities
Unknown; insufficient technical data provided.
Potential impact on your site
04Site Impact
Unknown impact; vendor and patch status unclear.
Conditions required to exploit
05Prerequisites
Unknown; insufficient technical data provided.
Key dates
06Disclosure timeline
May 11, 2026
CVE published
May 11, 2026
Record updated