Remote Code Execution Vulnerability in Premmerce Dev Tools for WordPress
CVE-2026-6933
8.8HIGH
What is CVE-2026-6933?
The Premmerce Dev Tools plugin for WordPress has a critical security flaw that allows remote code execution due to insufficient authorization checks in the 'generatePluginHandler' function. The vulnerability stems from the lack of validation on user-supplied POST data, enabling attackers to inject malicious PHP code. By manipulating the 'premmerce_plugin_namespace' parameter, authenticated users with Subscriber-level access or greater can generate and execute harmful PHP files on the server, risking the integrity and security of the website.
Affected Version(s)
Premmerce Dev Tools 0 <= 2.0