Easy PHP Settings

Easy PHP Settings has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Code Injection, behind 1 of the records (100%).

The one issue recorded for Easy PHP Settings has a vendor fix available, so running the current release closes it.

All of these findings were reported by ZAST.AI. Easy PHP Settings is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
7.2/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Easy PHP Settings vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2026-3352

Easy PHP Settings <= 1.0.4 - Authenticated (Administrator+) PHP Code Injection via 'wp_memory_limit' Setting

Read the full analysis

Vulnerability Records

1 records
Easy PHP Settings banner
Latestv1.1.8

Easy PHP Settings

shahadul878

Author

shahadul878

5.0(6)
100/100
Last Updated
2026-09-02 (10d ago)
Active Installs
1,000+
Downloads
11,866
Requires WP
5.0+
Requires PHP
7.2+
Tested up to
WP 7.1
Created
2025-08-12 (1y ago)

Easy PHP Settings provides a user-friendly interface to view and manage crucial PHP and WordPress configurations without needing to manually edit server files. It’s designed for both single-site and multisite installations, giving administrators the power to optimize their environment directly from the dashboard. Key Features: Manage PHP Settings: Easily modify the 5 core PHP settings (memory_limit, upload_max_filesize, post_max_size, max_execution_time, max_input_vars) through dedicated fields. Custom php.ini Configuration: Add any additional PHP directives (session settings, timezone, logging, file uploads, etc.) directly in the flexible custom configuration textarea. Quick Presets: Choose from pre-configured optimization profiles (Default, Performance, WooCommerce, Development, Large Media) that populate both core fields and custom php.ini directives automatically. WordPress Memory Management: Configure WordPress-specific memory limits including WP_MEMORY_LIMIT and WP_MAX_MEMORY_LIMIT to optimize your site’s performance. Automatic Configuration: When you save your settings, the plugin automatically generates .user.ini and php.ini files in your WordPress root directory. Configuration Generator: For locked-down environments, the plugin provides a generator to create configuration snippets that you can manually add to your server files. PHP Extensions Viewer: View all loaded PHP extensions categorized by type, with indicators for critical missing extensions and recommendations. Settings Validation: Automatically detects potentially problematic configuration values and warns you before saving. Settings History: Track all changes made to your settings with the ability to restore previous configurations. Export history as CSV. Import/Export: Backup your settings as JSON files and migrate configurations between sites effortlessly. One-Click Reset: Reset to recommended values or server defaults with automatic backup creation. Helpful Tooltips: Hover over help icons next to each setting to understand what it does and why it matters. Live Status Checker: A dedicated “Status” tab shows your current server environment, including PHP version, server software, and a comparison of current vs. recommended PHP values. WordPress Debugging: A “Debugging” tab with on/off switches lets you easily toggle WP_DEBUG, WP_DEBUG_LOG, WP_DEBUG_DISPLAY, and SCRIPT_DEBUG constants in your wp-config.php file. Multisite Compatible: On multisite networks, settings are managed at the network level by Super Admins. This plugin is perfect for developers and site administrators who want a quick and safe way to view and adjust their site’s technical settings. Privacy & data sharing: Easy PHP Settings includes an optional, default-off integration with Plugin Tracker (CodeEyes) at https://plugin.codereyes.com/. No data is sent until an administrator explicitly opts in from the About tab or the optional admin notice. If you opt in, the following may be transmitted: site URL; WordPress, PHP, and plugin versions; server software; administrator email and display name; and lists of installed plugins and themes (name, version, active status). Data is sent once when you opt in, then at most once per week (scheduled task), at most once per hour during admin use, after plugin updates, and once on deactivation if you had opted in. Purpose: improve plugin support and related services/offers. You can revoke consent at any time under Tools → Easy PHP Settings → About → Privacy & Data Sharing. The plugin works fully without enabling data sharing. See the Privacy Policy section below for full details. Pro Features Upgrade to Easy PHP Settings Pro for advanced controls, automation, and tooling designed for performance, safety, and team productivity. Advanced PHP & Server Controls Manage all PHP INI directives (memory, upload, post size, execution time, input vars, OPcache, sessions, error_reporting). Advanced Config Generator (Apache .htaccess, NGINX snippets, cPanel/LiteSpeed compatibility). Per-site overrides in Multisite (instead of only Network Admin). PHP Extension Checker → Detects missing extensions (imagick, intl, bcmath, etc.) and gives install guidance. Real-time Server Health Monitor → CPU, RAM, disk usage, PHP-FPM pool stats. Optimization & Performance One-click Optimization Profiles (ready presets): WooCommerce Stores Elementor / Page Builders LMS (LearnDash, TutorLMS) High Traffic Blogs Multisite Networks Smart Recommendations → Suggest best values based on your hosting/server. OPcache Manager → Enable/disable and tune OPcache. Safety & Reliability Backup & Restore Configurations (before/after editing .user.ini & php.ini). Safe Mode → If wrong values break the site, plugin auto-rolls back to last working config. Error Log Viewer → View PHP error logs and debug logs directly from dashboard. Email Alerts & Notifications → Sends warnings if PHP limits are too low, or site hits memory/time limits. Productivity & Agency Tools Import / Export Settings → Save your preferred config and apply on other sites. Multi-Site Templates → Apply one config across the network. White-label Option → Rebrand plugin for agencies (hide “Easy PHP Settings” branding). Role-based Access → Allow only specific roles (like Admins, Developers) to change PHP settings. Premium Experience Priority Support (faster replies, email/ticket). Regular Pro Updates with new hosting compatibility. Advanced Documentation & Tutorials (step-by-step setup guides). Summary (Pro Highlights) Advanced Settings (all directives, OPcache, sessions) Profiles (WooCommerce, LMS, high traffic, etc.) Monitoring (server health, error logs) Backup/Restore + Safe Mode Import/Export & Agency Tools Alerts & Notifications Premium Support Privacy Policy This plugin can optionally send site information to a third-party service when an administrator explicitly opts in. Data sharing is disabled by default. Third-party service: Plugin Tracker (CodeEyes) — https://plugin.codereyes.com/ Privacy Policy: https://codereyes.com/privacy-policy/ Terms of Service: https://github.com/shahadul878/easy-php-settings/blob/master/legal/plugin-tracker-terms.md Data that may be sent after opt-in: * Site URL * WordPress, PHP, and Easy PHP Settings plugin versions * Server software * Administrator email address and display name * Installed plugins and themes (name, version, active status) When data is sent: Once when you opt in; then at most once per week via a scheduled task; at most once per hour during admin dashboard use; after plugin updates; and once on plugin deactivation if you had opted in. Purpose: Improve plugin support, service updates, and optional offers from the developer. How to enable or revoke: Go to Tools → Easy PHP Settings → About → Privacy & Data Sharing. Use Allow data sharing to opt in or Revoke consent to stop all future transmission and clear scheduled sync tasks. No data before opt-in: Activating or using Easy PHP Settings does not send any information to plugin.codereyes.com until you explicitly allow it. External services Easy PHP Settings can optionally connect to Plugin Tracker, a service operated by CodeEyes at https://plugin.codereyes.com/. This is used only after an administrator opts in from Tools → Easy PHP Settings → About. The plugin works fully without this connection. What the service is used for: Plugin support, compatibility insight, and optional service offers related to Easy PHP Settings. What data is sent and when: After opt-in, the plugin may send the site URL; WordPress, PHP, and plugin versions; server software; the administrator email address and display name; and installed plugins and themes (name, version, active status). Data may be sent once on opt-in, at most once per week on a schedule, at most once per hour during wp-admin use, after plugin updates, and once on deactivation if you had opted in. Terms of Service: https://github.com/shahadul878/easy-php-settings/blob/master/legal/plugin-tracker-terms.md Privacy Policy: https://codereyes.com/privacy-policy/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C