plugin

Header And Footer Script Adder Vulnerabilities

2 known security issues reported for the Header And Footer Script Adder WordPress plugin. Most recent disclosed Jul 22, 2026.

2 medium

Running Header And Footer Script Adder on your site? Check whether your installed version is affected.

Scan your site free

Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'asm_code' Snippet Meta

medium

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

CVSS:
6.4
Affected:
up to 2.1
Fixed in:
2.1.1
Disclosed:
Jul 22, 2026

CVE-2026-15394 on NVD →

Header Footer Script Adder – Insert Code in Header, Body & Footer <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the script adder present in posts in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...

CVSS:
6.4
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Dec 12, 2025

CVE-2025-12109 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database