plugin

Code Snippets Vulnerabilities

16 known security issues reported for the Code Snippets WordPress plugin. Most recent disclosed Feb 5, 2026.

2 high 5 medium

Running Code Snippets on your site? Check whether your installed version is affected.

Scan your site free

Code Snippets <= 3.9.4 - Cross-Site Request Forgery to Cloud Snippet Download/Update Actions

medium

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download and update actions in the Cloud_Search_List_Table class. This makes it possible for unauthenticated attackers to force log...

CVSS:
4.3
Affected:
up to 3.9.4
Fixed in:
3.9.5
Disclosed:
Feb 5, 2026

CVE-2026-1785 on NVD →

Code Snippets [code-snippets] < 3.9.2

unknown

[en] The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` vari...

Affected:
up to 3.9.2
Fixed in:
3.9.2
Disclosed:
Nov 19, 2025

CVE-2025-13035 on NVD →

Code Snippets <= 3.9.1 - Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains

high

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable...

CVSS:
8
Affected:
up to 3.9.1
Fixed in:
3.9.2
Disclosed:
Nov 18, 2025

CVE-2025-13035 on NVD →

Code Snippets [code-snippets] < 3.6.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Code Snippets Pro Code Snippets.This issue affects Code Snippets: from n/a through 3.5.0.

Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Nov 18, 2023

CVE-2023-47666 on NVD →

Code Snippets <= 3.5.0 - Cross-Site Request Forgery via load

medium

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.5.0. This is due to missing or incorrect nonce validation on the load function. This makes it possible for unauthenticated attackers to reset plugin settings via a forged request granted they can tri...

CVSS:
5.4
Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Nov 6, 2023

CVE-2023-47666 on NVD →

Code Snippets [code-snippets] < 3.6.0

unknown

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.5.0. This is due to missing or incorrect nonce validation on the load function. This makes it possible for unauthenticated attackers to reset plugin settings via a forged request granted they can tri...

Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Nov 6, 2023

Code Snippets <= 2.14.3 - Reflected Cross-Site Scripting

medium

Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.

CVSS:
4.7
Affected:
up to 2.14.3
Fixed in:
2.14.4
Disclosed:
May 18, 2022

CVE-2022-25617 on NVD →

Code Snippets [code-snippets] < 2.14.4

unknown

[en] Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.

Affected:
up to 2.14.4
Fixed in:
2.14.4
Disclosed:
May 18, 2022

CVE-2022-25617 on NVD →

Code Snippets [code-snippets] < 2.14.3

unknown

[en] The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 2.14.3
Fixed in:
2.14.3
Disclosed:
Jan 24, 2022

CVE-2021-25008 on NVD →

Code Snippets <= 2.14.2 - Reflected Cross-Site Scripting

medium

The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 2.14.3
Fixed in:
2.14.3
Disclosed:
Dec 27, 2021

CVE-2021-25008 on NVD →

Code Snippets <= 2.13.3 - Cross-Site Request Forgery to Remote Code Execution

high

The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.

CVSS:
8.8
Affected:
up to 2.13.3
Fixed in:
2.14.0
Disclosed:
Jan 29, 2020

CVE-2020-8417 on NVD →

Code Snippets [code-snippets] < 2.14.0

unknown

[en] The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.

Affected:
up to 2.14.0
Fixed in:
2.14.0
Disclosed:
Jan 28, 2020

CVE-2020-8417 on NVD →

Code Snippets < 2.7.0 - Reflected Cross-Site Scripting

medium

The Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tag’ parameter in versions before 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Jul 24, 2016

Code Snippets [code-snippets] < 2.7.0

unknown

Because of this vulnerability, attacker can inject malicious JavaScript code into the application. Update the plugin.

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Jul 24, 2016

Code Snippets [code-snippets] < 2.7.0

unknown

The Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tag’ parameter in versions before 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Jul 24, 2016

Code Snippets [code-snippets] < 2.7.0

unknown

The Code Snippets WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.7.0
Fixed in:
2.7.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database