PT-2026-33983 · Undefined · Undefined

John Umoru

·

Published

2026-04-21

·

Updated

2026-05-16

·

CVE-2026-6433

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Custom css-js-php versions prior to 2.0.8
Description The plugin fails to properly sanitize user input before incorporating it into a SQL query. The resulting output is then passed to the eval() function, which enables unauthenticated users to execute arbitrary PHP code on the server. This process involves a SQL injection (SQLi) leading to Remote Code Execution (RCE), where an attacker can run commands on the host operating system from a remote machine.
Recommendations Update to a version newer than 2.0.7.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-6433

Affected Products

Undefined