A significant vulnerability (CVE-2026-45293) in the WordPress Coding Standards (WordPressCS) allows arbitrary code execution when PHP code is linted using the tool. This flaw, rated 8.6 on the CVSS scale, affects versions between 0.14.1 and 3.4.1. The risk arises when untrusted PHP code is evaluated during scans, potentially leading to exploitation through compromised pull requests. While currently no confirmed exploit exists, it is advised that users upgrade to version 3.4.1 to mitigate the risk. The vulnerability affects only developers and CI systems that lint code.
CVE-2026-45293 flaw in WordPressCS lets code run via PHP lint
CyberSIXT Evidence Panel
Article by CyberSIXT