
CVE-2025-6784 The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to … https://www.cve.org/CVERecord?id=CVE-2025-6784
Post summary
The Code Engine WordPress plugin up to version 0.3.5 is vulnerable to Remote Code Execution via the 'code-engine' shortcode. Details are documented on CVE-2025‑6784 but no PoC, exploit code, or patch has been provided.



