WordPress Coding Standards (WordPressCS) fixed CVE-2026-45293 / GHSA-3pwp-g2mj-5p3v, an arbitrary command-execution flaw in the WordPress.WP.EnqueuedResourceParameters sniff that affected versions 0.14.1 through 3.4.0. The bug stemmed from use of eval() in the is_falsy() method while reconstructing the $ver argument passed to functions such as wp_enqueue_script(), allowing crafted PHP like ('system')('id') in scanned code to execute commands on the machine running PHP_CodeSniffer. The risk is highest where untrusted PHP is linted in CI pipelines or reviewed on developer workstations.
The project released WordPressCS 3.4.1 and urged immediate upgrades, noting that the issue affects the WordPress and WordPress-Extra rulesets but not WordPress-Core or WordPress-Docs. The fix, merged in pull request #2771 and commit a29048d0bbef5cf25d42349c74e4072d3cbc8325, removes eval() and replaces it with explicit token-level checks for limited literal falsy values such as false, 0, '0', '', and empty arrays; maintainers also updated tests and raised minimum dependencies to PHPCSUtils 1.2.3 and PHPCSExtra 1.5.1.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-27, WordPress Coding Standards released version 3.4.1 as a security update and urged users to upgrade immediately. The release fixed the arbitrary command execution flaw affecting the WordPress and WordPress-Extra rulesets when scanning untrusted PHP code.
On 2026-07-27, WordPress Coding Standards merged pull request #2771 into develop to remove eval() from the is_falsy() logic in WP/EnqueuedResourceParameters. The patch replaced eval()-based handling with explicit token-level checks for limited falsy literal values.
WordPress Coding Standards credited FORIMOC for responsibly disclosing the vulnerability later tracked as CVE-2026-45293 / GHSA-3pwp-g2mj-5p3v. The issue affected the WordPress.WP.EnqueuedResourceParameters sniff and could lead to arbitrary command execution when scanning untrusted PHP code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.