CVE-2025-6784Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the plugin. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-11); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-11: 3Mentions · 2026-09-30: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-11: 307-1109-30
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-6784 The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to … https://www.cve.org/CVERecord?id=CVE-2025-6784

    Post summary

    The Code Engine WordPress plugin up to version 0.3.5 is vulnerable to Remote Code Execution via the 'code-engine' shortcode. Details are documented on CVE-2025‑6784 but no PoC, exploit code, or patch has been provided.

    00010661
    57.8K followersView on X
  • DFIR Lab@DFIR_Lab

    🚨 HIGH SEVERITY: CVE-2025-6784 (CVSS 8.8) Code Engine WordPress plugin ≤0.3.5 vulnerable to Remote Code Execution. Authenticated attackers (Contributor+) can execute arbitrary code via 'code-engine' shortcode. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/yFM6Xitqtb

    0000035
    143 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    WordPress Code Engine plugin vulnerable to RCE (CVE-2025-6784, CVSS 8.8). Update immediately if used. https://nvd.nist.gov/vuln/detail/CVE-2025-6784 http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/2bNT0qaFi8

    Post summary

    The tweet announces CVE‑2025‑6784 as a high‑score RCE vulnerability in the WordPress Code Engine plugin and urges users to update immediately, but does not provide a PoC or exploit code.

    0000042
    89 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-6784 The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to … https://www.cve.org/CVERecord?id=CVE-2025-6784 ----- Traducción: CVE-2025-6784 El … http://infoflow.cloud`

    Post summary

    The post discloses that the WordPress Code Engine plugin (v0.3.5 and earlier) is vulnerable to RCE via a shortcode, without providing PoC, exploit, patch, or evidence of active exploitation.

    0000024
    92 followersView on X

Explore more