CVE-2026-106095
Received Received - Intake

Code Snippets Plugin Privilege Escalation via Network-Scope Manipulation

Vulnerability report for CVE-2026-106095, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: WPScan

Description

The Code Snippets WordPress plugin before 3.10.0 does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allowing an administrator of a single subsite on a multisite network to activate, deactivate and reprioritise network-scoped snippets that run across every site in the network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Code Snippets 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Code Snippets WordPress plugin before version 3.10.0 has a flaw where it does not check if an administrator has the proper permissions before allowing them to manage network-scoped snippets. Instead, it relies on the request to determine the scope, letting a single subsite admin activate, deactivate, or change the priority of snippets that run across the entire network.

Detection Guidance

Check the installed version of the Code Snippets plugin. If it is below 3.10.0, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

If you are an administrator on a single site within a WordPress multisite network using an outdated Code Snippets plugin, an attacker with admin access to your subsite could manipulate network-wide snippets. This could lead to unauthorized code execution, data breaches, or disruption of services across all sites in the network.

Compliance Impact

This vulnerability could lead to unauthorized access or modifications across a network, potentially violating data protection requirements under GDPR or HIPAA. Unauthorized code execution might expose sensitive data or disrupt compliance controls, increasing legal and regulatory risks.

Mitigation Strategies

Update the Code Snippets plugin to version 3.10.0 or later immediately. Remove admin access for untrusted users on subsites in a multisite network until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106095. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart