plugin

Insert Headers And Footers Vulnerabilities

7 known security issues reported for the Insert Headers And Footers WordPress plugin. Most recent disclosed May 26, 2026.

1 high 3 medium

Running Insert Headers And Footers on your site? Check whether your installed version is affected.

Scan your site free

WPCode <= 2.3.5 - Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost

high

The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3.5 This is due to the 'wpcode' custom post type being registered without a custom capability_type or capability restrictions in the wpc...

CVSS:
8.8
Affected:
up to 2.3.5
Fixed in:
2.3.6
Disclosed:
May 26, 2026

CVE-2026-8832 on NVD →

WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1

unknown

[en] The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 2.0.13.1
Fixed in:
2.0.13.1
Disclosed:
Aug 7, 2023

CVE-2023-3524 on NVD →

WPCode <= 2.0.13 - Unauthenticated Reflected Cross-Site Scripting via Tag Filter Links

medium

The WPCode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via tag filter links in versions up to, and including 2.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wheneve...

CVSS:
6.1
Affected:
up to 2.0.13
Fixed in:
2.0.13.1
Disclosed:
Jul 17, 2023

CVE-2023-3524 on NVD →

WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.0.9

unknown

[en] The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog...

Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Apr 24, 2023

CVE-2023-1624 on NVD →

WPCode <= 2.0.8 - Cross-Site Request Forgery

medium

The WPCode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on the maybe_delete_log function. This makes it possible for unauthenticated attackers to delete arbitrary log files via a forged request granted they...

CVSS:
4.7
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
Apr 3, 2023

CVE-2023-1624 on NVD →

WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.0.7

unknown

[en] The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Mar 6, 2023

CVE-2023-0328 on NVD →

WPCode <= 2.0.6 - Missing Authorization to Sensitive Key Disclosure/Update

medium

The WPCode plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the ajax_auth_url, store_auth_key, and delete_auth functions in versions up to, and including, 2.0.6. This makes it possible for authenticated attackers with access to edit_posts, such as c...

CVSS:
5.4
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Feb 9, 2023

CVE-2023-0328 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database