All vulnerabilities
CVE-2026-106095
Low
CVSS 3.3
Code Snippets < 3.10.0 – Admin+ Network-Scoped Snippet Activation and Deactivation via update_code_snippet
| Vendor | Code Snippets |
|---|---|
| Product | Code Snippets (WordPress plugin) |
| Affected versions | 3.10.0 |
| Weakness | CWE-862 |
| Reported | 2026-01-22 |
| Disclosed | 2026-10-07 |
| Status | Published |
The Code Snippets plugin for WordPress does not perform a capability check on a snippet-management action and derives the target snippet's network scope from the request rather than the stored record. This allows an administrator of a single subsite in a Multisite network to activate, deactivate, and reprioritize network-scoped snippets across the network.
Impact
An administrator of a single subsite may change the activation state and priority of network-scoped snippets that run across the Multisite network, potentially affecting the behavior of multiple sites.
Related disclosures
Low
The Events Calendar 6.15.16.1 – 6.17.4.1 – Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes
Medium
Kirki 6.0.0 – 6.3.0 – Author+ Stored XSS via Unsanitized SVG Upload
Medium
Kirki Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter
Low
The Events Calendar — Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API
View all