{"id":"CVE-2026-106095","title":"The Code Snippets WordPress plugin before 3.10.0 does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allow…","summary":"The Code Snippets WordPress plugin before 3.10.0 does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allow…","severity":"none","published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T07:17:17.897","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106095","references":[{"url":"https://wpscan.com/vulnerability/4aeddbb6-d7a9-48cb-96ea-5898586bce04/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T07:28:22.264Z","slug":"CVE-2026-106095","body":"## Overview\n\nThe Code Snippets WordPress plugin before 3.10.0 does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allowing an administrator of a single subsite on a multisite network to activate, deactivate and reprioritise network-scoped snippets that run across every site in the network.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}