CVE-2026-6433Disclosure

HIGHCVSS 7.3 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.

7.5/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-04-21); latest day: 1
  • 6 total mentions across 6 days

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-04-21: 1Mentions · 2026-05-11: 1Mentions · 2026-05-16: 1Mentions · 2026-07-12: 1Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-05-16: 1Exploit Tool / Code · 2026-05-16: 1Active Exploitation · 2026-07-12: 1Patch / Workaround · 2026-09-16: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-16: 1Technical Details · 2026-09-16: 104-2105-1105-1607-1209-1609-17
Signal classification5 categories
Disclosure
233.3%
PoC
116.7%
Active Exploitation
116.7%
Patch
116.7%
False Positive
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-05-111
Disclosure1
2026-05-161
PoC1
2026-07-121
Active Exploitation1
2026-09-161
Patch1
2026-09-171
False Positive1
Full discourse6 posts
  • Dr. John Umoru@johnumorujo
    Disclosure

    My first CVE in the bag: CVE-2026-6433 https://wpscan.com/vulnerability/a0b1c059-e156-4402-ac8d-67f8ad7386cc/ Unauthenticated sqli → RCE on FlipperCode's Custom CSS, JS & PHP plugin (≤ 2.0.7). CVSS 10.0 🎯 wpscan showed no plugins with any serious vulnerabilities, I turned my eyes to source code review and dynamic testing in docker; and there you have it. #BugBounty #WordPress #CVE #InfoSec #RCE #SQLi #AppSec #CyberSecurity

    Post summary

    CVE-2026-6433 reveals an unauthenticated SQL injection that escalates to remote code execution in FlipperCode's Custom CSS, JS & PHP plugin (≤2.0.7), scoring CVSS 10.0, discovered through source‑code review and dynamic testing.

    15147162.8K
    751 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    Saldırganların WordPress, Joomla gibi sistemlere saldırırken kullandığı CVE'ler : – CVE-2026-3844 (WordPress Breeze) – CVE-2026-48907 (Joomla JCE) Diğerleri: CVE-2026-1969, CVE-2026-3300, CVE-2026-0740, CVE-2026-6433, CVE-2025-7443, CVE-2025-7852, CVE-2025-12057, CVE-2020-36847 ve CVE-2020-25213

    Post summary

    The post lists CVEs reportedly utilized by attackers against WordPress and Joomla, indicating active exploitation, but offers no PoC, exploit code, patch, or technical details.

    1301142.4K
    2.2K followersView on X
  • Dr. John Umoru@johnumorujo
    Patch

    Two unauthenticated RCEs were just disclosed in "The Events Calendar", a WordPress plugin with more than 600,000 active installs. They are tracked as CVE-2026-78159 and CVE-2026-78006, they are both scored 9.8 on the CVSS score and can both lead to a full site takeover. About 200,000 sites are estimated to be vulnerable. I have seen this kind of bug before. During a client pentest, I found an unauthenticated SQL injection in FlipperCode’s Custom CSS, JS & PHP plugin. I was able to chain it all the way to remote code execution. That vulnerability became CVE-2026-6433. It was unauthenticated, meaning no admin or user credentials were needed and If the plugin was installed on a website, I could have a shell on the host. This is the same pattern, just on a much bigger plugin. A lot of organisations treat the company website as a marketing page. It is also an internet-facing application, running plugins written by people you have never met. For a bank, a hospital, a fintech, or a capital-markets operator here, that site is part of the same attack surface as everything else you are trying to protect. A scanner will not find a zero-day that is yet to be disclosed. However, an experienced pentester knows when to look under the hood and find a bug that others will ignore, just like a motivated attacker would. If you run WordPress, check whether The Events Calendar is installed. If it is, please update it to 6.17.4.1 or later. Also, do not wait for the next advisory. Have your website tested the way an attacker would. At @clarensecltd we include in-depth WordPress reviews in our assessments. You can send a message to info@clarensec.com or visit https://clarensec.com/contact hashtag#WordPress hashtag#CyberSecurity hashtag#VAPT

    Post summary

    Two high-severity unauthenticated RCE vulnerabilities (CVE-2026-78159, CVE-2026-78006) in The Events Calendar WordPress plugin are disclosed, with a specific patch version (6.17.4.1) recommended for immediate remediation. The text emphasizes technical details and the urgency of updating due to widespread exposure.

    20093514
    1.1K followersView on X
  • mürrez@murrezsec
    PoC

    PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk multi-threaded scanning. Authorized testing & research only. http://github.com/murrez/CVE-2026-6433 https://t.co/YOHtXGlzZp

    Post summary

    A PoC script demonstrating unauthenticated SQL injection to remote code execution in WordPress FlipperCode (≤2.0.7) has been released on GitHub; no active exploitation or patch information is provided.

    00021187
    591 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6433 The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing … https://www.cve.org/CVERecord?id=CVE-2026-6433

    Post summary

    The CVE‑2026‑6433 flaw in the Custom css‑js‑php WordPress plugin allows unsanitized user input to be used in a SQL query and passed to eval(), potentially enabling remote code execution.

    00020150
    57.8K followersView on X
  • WPSec - WordPress Security Scanner@WPSecScanner
    False Positive

    @johnumorujo Sorry, CVE-2026-6433 does not affect the events calendar

    Post summary

    The tweet denies that CVE‑2026‑6433 affects the events calendar, effectively debunking a claim of its relevance. No technical details, exploits, patches, or evidence of active exploitation are provided.

    1000081
    7.9K followersView on X

Explore more