Input validation vulnerability in Code Snippets 3.9.1

The Code Snippets plugin for WordPress is not secure and can be hacked by attackers. This is because the plugin uses a method called `evaluate_shortcode_from_flat_file` which allows attackers to control the attributes of the code. This can let them change important variables and execute their own code on the server. This can only be done by someone with Contributor-level access or higher, and only if they can convince an administrator to enable a certain setting and create a snippet.

Detected in:

Code Snippets fixed vulnerable versions: >= * <= 3.9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.