Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch affected systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.
My first CVE in the bag: CVE-2026-6433
https://wpscan.com/vulnerability/a0b1c059-e156-4402-ac8d-67f8ad7386cc/
Unauthenticated sqli → RCE on FlipperCode's Custom CSS, JS & PHP plugin (≤ 2.0.7).
CVSS 10.0 🎯
wpscan showed no plugins with any serious vulnerabilities, I turned my eyes to source code review and dynamic testing in docker; and there you have it.
#BugBounty#WordPress#CVE#InfoSec#RCE#SQLi#AppSec#CyberSecurity
Post summary
CVE-2026-6433 reveals an unauthenticated SQL injection that escalates to remote code execution in FlipperCode's Custom CSS, JS & PHP plugin (≤2.0.7), scoring CVSS 10.0, discovered through source‑code review and dynamic testing.
Saldırganların WordPress, Joomla gibi sistemlere saldırırken kullandığı CVE'ler :
– CVE-2026-3844 (WordPress Breeze)
– CVE-2026-48907 (Joomla JCE)
Diğerleri: CVE-2026-1969, CVE-2026-3300, CVE-2026-0740, CVE-2026-6433, CVE-2025-7443, CVE-2025-7852, CVE-2025-12057, CVE-2020-36847 ve CVE-2020-25213
Post summary
The post lists CVEs reportedly utilized by attackers against WordPress and Joomla, indicating active exploitation, but offers no PoC, exploit code, patch, or technical details.
Two unauthenticated RCEs were just disclosed in "The Events Calendar", a WordPress plugin with more than 600,000 active installs.
They are tracked as CVE-2026-78159 and CVE-2026-78006, they are both scored 9.8 on the CVSS score and can both lead to a full site takeover. About 200,000 sites are estimated to be vulnerable.
I have seen this kind of bug before. During a client pentest, I found an unauthenticated SQL injection in FlipperCode’s Custom CSS, JS & PHP plugin. I was able to chain it all the way to remote code execution. That vulnerability became CVE-2026-6433. It was unauthenticated, meaning no admin or user credentials were needed and If the plugin was installed on a website, I could have a shell on the host.
This is the same pattern, just on a much bigger plugin. A lot of organisations treat the company website as a marketing page. It is also an internet-facing application, running plugins written by people you have never met. For a bank, a hospital, a fintech, or a capital-markets operator here, that site is part of the same attack surface as everything else you are trying to protect.
A scanner will not find a zero-day that is yet to be disclosed. However, an experienced pentester knows when to look under the hood and find a bug that others will ignore, just like a motivated attacker would.
If you run WordPress, check whether The Events Calendar is installed. If it is, please update it to 6.17.4.1 or later. Also, do not wait for the next advisory. Have your website tested the way an attacker would.
At @clarensecltd we include in-depth WordPress reviews in our assessments. You can send a message to info@clarensec.com or visit https://clarensec.com/contact
hashtag#WordPress hashtag#CyberSecurity hashtag#VAPT
Post summary
Two high-severity unauthenticated RCE vulnerabilities (CVE-2026-78159, CVE-2026-78006) in The Events Calendar WordPress plugin are disclosed, with a specific patch version (6.17.4.1) recommended for immediate remediation. The text emphasizes technical details and the urgency of updating due to widespread exposure.
PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk multi-threaded scanning. Authorized testing & research only.
http://github.com/murrez/CVE-2026-6433 https://t.co/YOHtXGlzZp
Post summary
A PoC script demonstrating unauthenticated SQL injection to remote code execution in WordPress FlipperCode (≤2.0.7) has been released on GitHub; no active exploitation or patch information is provided.
CVE-2026-6433 The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing … https://www.cve.org/CVERecord?id=CVE-2026-6433
Post summary
The CVE‑2026‑6433 flaw in the Custom css‑js‑php WordPress plugin allows unsanitized user input to be used in a SQL query and passed to eval(), potentially enabling remote code execution.
@johnumorujo Sorry, CVE-2026-6433 does not affect the events calendar
Post summary
The tweet denies that CVE‑2026‑6433 affects the events calendar, effectively debunking a claim of its relevance. No technical details, exploits, patches, or evidence of active exploitation are provided.