CVE-2026-45293: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in WordPress WordPress-Coding-Standards
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as wp_enqueue_script() and ran it through eval() inside its is_falsy() method, so a maliciously crafted argument such as 'system'('id') would execute during a scan; as a result, running PHPCS with WordPressCS over untrusted PHP (for example a CI pipeline that lints pull requests, or a developer reviewing third-party code) could lead to arbitrary command execution on the scanning host. The WordPress-Core and WordPress-Docs rulesets are not affected. This issue is fixed in version 3.4.1.
AI Analysis
Technical Summary
WordPress Coding Standards is a set of PHP_CodeSniffer rules enforcing WordPress coding conventions. From versions 0.14.1 until 3.4.0, the WordPress.WP.EnqueuedResourceParameters sniff reconstructed the $ver argument passed to functions like wp_enqueue_script() and evaluated it using eval() inside its is_falsy() method. This unsafe evaluation allows maliciously crafted input (e.g., 'system'('id')) to execute arbitrary commands on the scanning host during a PHPCS run. This vulnerability does not affect the WordPress-Core or WordPress-Docs rulesets. The vulnerability is resolved in version 3.4.1.
Potential Impact
An attacker who can supply or influence PHP code scanned by PHP_CodeSniffer with the vulnerable WordPress Coding Standards ruleset can execute arbitrary commands on the host performing the scan. This can lead to full compromise of the scanning environment, including confidentiality, integrity, and availability impacts. The vulnerability requires local access to run PHPCS or the ability to trigger scans on untrusted code, such as in automated CI pipelines.
Mitigation Recommendations
A fix is available in WordPress Coding Standards version 3.4.1. Users should upgrade to version 3.4.1 or later to remediate this vulnerability. Until upgraded, avoid scanning untrusted PHP code with the WordPress or WordPress-Extra rulesets that include the vulnerable sniff. The WordPress-Core and WordPress-Docs rulesets are not affected and can be used as alternatives if scanning untrusted code is necessary.
CVE-2026-45293: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in WordPress WordPress-Coding-Standards
Description
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as wp_enqueue_script() and ran it through eval() inside its is_falsy() method, so a maliciously crafted argument such as 'system'('id') would execute during a scan; as a result, running PHPCS with WordPressCS over untrusted PHP (for example a CI pipeline that lints pull requests, or a developer reviewing third-party code) could lead to arbitrary command execution on the scanning host. The WordPress-Core and WordPress-Docs rulesets are not affected. This issue is fixed in version 3.4.1.
CVSS v3.1
Score 8.6high
Affected software
WordPress
WordPress-Coding-Standards
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
WordPress Coding Standards is a set of PHP_CodeSniffer rules enforcing WordPress coding conventions. From versions 0.14.1 until 3.4.0, the WordPress.WP.EnqueuedResourceParameters sniff reconstructed the $ver argument passed to functions like wp_enqueue_script() and evaluated it using eval() inside its is_falsy() method. This unsafe evaluation allows maliciously crafted input (e.g., 'system'('id')) to execute arbitrary commands on the scanning host during a PHPCS run. This vulnerability does not affect the WordPress-Core or WordPress-Docs rulesets. The vulnerability is resolved in version 3.4.1.
Potential Impact
An attacker who can supply or influence PHP code scanned by PHP_CodeSniffer with the vulnerable WordPress Coding Standards ruleset can execute arbitrary commands on the host performing the scan. This can lead to full compromise of the scanning environment, including confidentiality, integrity, and availability impacts. The vulnerability requires local access to run PHPCS or the ability to trigger scans on untrusted code, such as in automated CI pipelines.
Mitigation Recommendations
A fix is available in WordPress Coding Standards version 3.4.1. Users should upgrade to version 3.4.1 or later to remediate this vulnerability. Until upgraded, avoid scanning untrusted PHP code with the WordPress or WordPress-Extra rulesets that include the vulnerable sniff. The WordPress-Core and WordPress-Docs rulesets are not affected and can be used as alternatives if scanning untrusted code is necessary.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-11T20:14:43.201Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a68d75f9c2644c7f8e0509f
Added to database: 07/28/2026, 16:22:55 UTC
Last enriched: 07/29/2026, 16:53:46 UTC
Last updated: 09/12/2026, 22:01:34 UTC
Views: 40
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.