CVE-2017-20251 - CVE House
Back to Database
Status published Critical CVE-2017-20251

WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API

Vulnerability Description

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with crafted content containing insert_php shortcodes to include and execute remote PHP files on the server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-20251

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • sucuri.net @sucurisecurity

Affected Vendor

Affected Software

Woody Code Snippets
Vulnerable Versions:
0

Timeline

Official Publish: June 9th, 2026
Last Modified: June 9th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)