Code Snippets <= 3.9.4 - Cross-Site Request Forgery to Cloud Snippet Download/Update Actions
medium
The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download and update actions in the Cloud_Search_List_Table class. This makes it possible for unauthenticated attackers to force log...
- CVSS:
- 4.3
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.5
- Disclosed:
- Feb 5, 2026
CVE-2026-1785 on NVD →
Code Snippets [code-snippets] < 3.9.2
unknown
[en] The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` vari...
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Nov 19, 2025
CVE-2025-13035 on NVD →
Code Snippets <= 3.9.1 - Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains
high
The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable...
- CVSS:
- 8
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.2
- Disclosed:
- Nov 18, 2025
CVE-2025-13035 on NVD →
Code Snippets [code-snippets] < 3.6.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Code Snippets Pro Code Snippets.This issue affects Code Snippets: from n/a through 3.5.0.
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Nov 18, 2023
CVE-2023-47666 on NVD →
Code Snippets <= 3.5.0 - Cross-Site Request Forgery via load
medium
The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.5.0. This is due to missing or incorrect nonce validation on the load function. This makes it possible for unauthenticated attackers to reset plugin settings via a forged request granted they can tri...
- CVSS:
- 5.4
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Nov 6, 2023
CVE-2023-47666 on NVD →
Code Snippets [code-snippets] < 3.6.0
unknown
The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.5.0. This is due to missing or incorrect nonce validation on the load function. This makes it possible for unauthenticated attackers to reset plugin settings via a forged request granted they can tri...
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Nov 6, 2023
Code Snippets <= 2.14.3 - Reflected Cross-Site Scripting
medium
Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.
- CVSS:
- 4.7
- Affected:
- up to 2.14.3
- Fixed in:
- 2.14.4
- Disclosed:
- May 18, 2022
CVE-2022-25617 on NVD →
Code Snippets [code-snippets] < 2.14.4
unknown
[en] Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.
- Affected:
- up to 2.14.4
- Fixed in:
- 2.14.4
- Disclosed:
- May 18, 2022
CVE-2022-25617 on NVD →
Code Snippets [code-snippets] < 2.14.3
unknown
[en] The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 2.14.3
- Fixed in:
- 2.14.3
- Disclosed:
- Jan 24, 2022
CVE-2021-25008 on NVD →
Code Snippets <= 2.14.2 - Reflected Cross-Site Scripting
medium
The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 2.14.3
- Fixed in:
- 2.14.3
- Disclosed:
- Dec 27, 2021
CVE-2021-25008 on NVD →
Code Snippets <= 2.13.3 - Cross-Site Request Forgery to Remote Code Execution
high
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
- CVSS:
- 8.8
- Affected:
- up to 2.13.3
- Fixed in:
- 2.14.0
- Disclosed:
- Jan 29, 2020
CVE-2020-8417 on NVD →
Code Snippets [code-snippets] < 2.14.0
unknown
[en] The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
- Affected:
- up to 2.14.0
- Fixed in:
- 2.14.0
- Disclosed:
- Jan 28, 2020
CVE-2020-8417 on NVD →
Code Snippets < 2.7.0 - Reflected Cross-Site Scripting
medium
The Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tag’ parameter in versions before 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Jul 24, 2016
Code Snippets [code-snippets] < 2.7.0
unknown
Because of this vulnerability, attacker can inject malicious JavaScript code into the application.
Update the plugin.
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Jul 24, 2016
Code Snippets [code-snippets] < 2.7.0
unknown
The Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tag’ parameter in versions before 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Jul 24, 2016
Code Snippets [code-snippets] < 2.7.0
unknown
The Code Snippets WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database