Vulnerabilities and security researches forcodepress-admin-columns codepress-admin-columns
Direction: descendingJun 07, 2026
Admin Columns # CVE-2026-7654
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 06, 2026
- Research Description
- The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()` function, which processes attacker-controlled post meta values without proper validation. This makes it possible for authenticated attackers with Contributor-level access and above to inject a serialized PHP object into a post's custom meta field and trigger arbitrary code execution by exploiting a bundled POP gadget chain, resulting in remote code execution as the web server user.
- Affected versions
-
max 7.0.19.
- Status
-
vulnerable
Jun 07, 2024
Admin Columns # CVE-2019-17661
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 08, 2019
- Research Description
- A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
- Affected versions
-
max 3.4.6.
- Status
-
vulnerable
Admin Columns # CVE-2021-24366
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 22, 2021
- Research Description
- The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
max 4.3.
- Status
-
vulnerable
Admin Columns # CVE-2021-24365
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 13, 2021
- Research Description
- The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.
- Affected versions
-
max 4.3.2.
- Status
-
vulnerable