PT-2026-63507 · Sorcerer · Sourcerer
CVE-2026-64796
·
Published
2026-07-22
·
Updated
2026-07-23
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sourcerer extension (affected versions not specified)
Description
Multiple code injection vectors exist within the extension. The Free version fails to verify that both the article creator and the last modifier possess Super User privileges before executing PHP code within an article. The Pro version does not consistently enforce permissions for CSS, JavaScript, and PHP across tags, attributes, files, and article owners. Additionally, PHP include attributes may allow escaping the configured include folder, and certain executable script or style variants can bypass detection mechanisms.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcerer