Skip to main content
Loading…
    CVE-2025-13035 — The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcod — CVE Database · The Intelligence Room