


Perceptive Security
SOC/SIEM Consultancy

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.Enque…
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 19:04:58
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies, Security Tools
CVE-2026-45293 affects WordPress Coding Standards (WordPressCS) versions 0.14.1 through 3.4.1. The WordPress.WP.EnqueuedResourceParameters sniff reconstructs the $ver argument passed to functions like wp_enqueue_script() and passes it through eval() in its is_falsy() method. A maliciously crafted PHP argument such as 'system'('id') can trigger arbitrary command execution on the host running the PHPCS scan. This vulnerability is especially dangerous in CI/CD pipelines that lint untrusted pull requests or when developers review third-party code. Only the WordPress and WordPress-Extra rulesets are affected; WordPress-Core and WordPress-Docs are not. The issue has been patched in version 3.4.1 of WordPress Coding Standards.
Technical details
Mitigation steps:
Affected products:
WordPress Coding Standards (WordPressCS)
PHP_CodeSniffer
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45293
https://github.com/WordPress/WordPress-Coding-Standards/commit/a29048d0bbef5cf25d42349c74e4072d3cbc8325
https://github.com/WordPress/WordPress-Coding-Standards/pull/2771
https://github.com/WordPress/WordPress-Coding-Standards/releases/tag/3.4.1
https://github.com/WordPress/WordPress-Coding-Standards/security/advisories/GHSA-3pwp-g2mj-5p3v
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
