Code Injection Vulnerability in WebsiteBaker CMS by WebsiteBaker
CVE-2026-61523
8.6HIGH
What is CVE-2026-61523?
A code injection vulnerability exists in the Droplets editor of WebsiteBaker CMS versions prior to 2.13.10. This flaw allows authenticated administrators to submit malicious content through the droplets Code field, leading to the injection of arbitrary PHP code. The unsanitized code is directly written to a publicly accessible PHP file, enabling attackers to exploit this vulnerability. By saving a PHP web shell via the save_droplet handler to a predictable path in the modules directory, unauthorized users can execute remote commands by sending HTTP requests to the vulnerable script, potentially compromising the entire server.
Affected Version(s)
WebsiteBaker CMS 0
