CVE-2026-61523
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to i
CVSS
7.2
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 3, 2026 · Last modified: Aug 3, 2026 · CWE-94
Not enough EPSS history yet.
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.
- addon.websitebaker.orghttps://addon.websitebaker.org/en/browse-add-ons/?type=5&cid=997
- medium.comhttps://medium.com/@benjaminasareagyapong2006/two-rce-vulnerabilities-i-found-on-my-birthday-evening-4563006a615a
- www.vulncheck.comhttps://www.vulncheck.com/advisories/websitebaker-cms-code-injection-via-droplets-editor