Description

The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP code to be entered by all users for whom unfiltered HTML is allowed. This makes it possible for authenticated attackers, with Editor-level access and above, to inject PHP code into posts and pages.

INFO

Published Date :

2025-03-08T02:24:03.309Z

Last Modified :

2026-04-08T16:48:36.489Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-13890 vulnerability.

Vendors Products
Sksdev
  • Allow Php Execute

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact