WPCode <= 2.3.5 - Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost
high
The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3.5 This is due to the 'wpcode' custom post type being registered without a custom capability_type or capability restrictions in the wpc...
- CVSS:
- 8.8
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.6
- Disclosed:
- May 26, 2026
CVE-2026-8832 on NVD →
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1
unknown
[en] The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 2.0.13.1
- Fixed in:
- 2.0.13.1
- Disclosed:
- Aug 7, 2023
CVE-2023-3524 on NVD →
WPCode <= 2.0.13 - Unauthenticated Reflected Cross-Site Scripting via Tag Filter Links
medium
The WPCode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via tag filter links in versions up to, and including 2.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wheneve...
- CVSS:
- 6.1
- Affected:
- up to 2.0.13
- Fixed in:
- 2.0.13.1
- Disclosed:
- Jul 17, 2023
CVE-2023-3524 on NVD →
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.9
unknown
[en] The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog...
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Apr 24, 2023
CVE-2023-1624 on NVD →
WPCode <= 2.0.8 - Cross-Site Request Forgery
medium
The WPCode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on the maybe_delete_log function. This makes it possible for unauthenticated attackers to delete arbitrary log files via a forged request granted they...
- CVSS:
- 4.7
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Apr 3, 2023
CVE-2023-1624 on NVD →
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.7
unknown
[en] The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Mar 6, 2023
CVE-2023-0328 on NVD →
WPCode <= 2.0.6 - Missing Authorization to Sensitive Key Disclosure/Update
medium
The WPCode plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the ajax_auth_url, store_auth_key, and delete_auth functions in versions up to, and including, 2.0.6. This makes it possible for authenticated attackers with access to edit_posts, such as c...
- CVSS:
- 5.4
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Feb 9, 2023
CVE-2023-0328 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database