All vulnerabilities
CVE-2026-106095 Low CVSS 3.3

Code Snippets < 3.10.0 – Admin+ Network-Scoped Snippet Activation and Deactivation via update_code_snippet

Vendor Code Snippets
Product Code Snippets (WordPress plugin)
Affected versions 3.10.0
Weakness CWE-862
Reported 2026-01-22
Disclosed 2026-10-07
Status Published
The Code Snippets plugin for WordPress does not perform a capability check on a snippet-management action and derives the target snippet's network scope from the request rather than the stored record. This allows an administrator of a single subsite in a Multisite network to activate, deactivate, and reprioritize network-scoped snippets across the network.

Impact

An administrator of a single subsite may change the activation state and priority of network-scoped snippets that run across the Multisite network, potentially affecting the behavior of multiple sites.

Related disclosures

View all