Jtsternberg maintains a narrowly scoped WordPress plugin called Code Snippets CPT that extends WordPress's code-management capabilities, introducing an application-layer attack surface centered on code injection risks. The vulnerability signal reflects the inherent danger of allowing user input to influence code generation and execution within a PHP environment, a structural concern for any tool that bridges user content and runtime code. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jtsternberg over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13895MEDIUM The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due to the software allowing user | Mar 8, 2025 | 6.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jtsternberg.
Media articles that mention a CVE ID that affects a product developed by Jtsternberg — matched by CVE ID, not by vendor name.