plugin

Insert Php Vulnerabilities

21 known security issues reported for the Insert Php WordPress plugin. Most recent disclosed Mar 23, 2026.

1 critical 3 high 4 medium

Running Insert Php on your site? Check whether your installed version is affected.

Scan your site free

Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts <= 2.7.1 - Authenticated (Contributor+) Remote Code Execution

high

The Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

CVSS:
8.8
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Mar 23, 2026

CVE-2026-25366 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.5.1

unknown

[en] The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This make...

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Jun 15, 2024

CVE-2024-3105 on NVD →

Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution

critical

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it...

CVSS:
9.9
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Jun 14, 2024

CVE-2024-3105 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.5.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Creative Motion, Will Bontrager Software, LLC Woody ad snippets allows Stored XSS.This issue affects Woody ad snippets: from n/a through 2.4.10.

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Jun 8, 2024

CVE-2024-35751 on NVD →

Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administr...

CVSS:
4.4
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Jun 6, 2024

CVE-2024-35751 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.3.10

unknown

[en] The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated attackers to activate and deactivate snippets via a forged...

Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Oct 20, 2023

CVE-2020-36759 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.3.10

unknown
Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.4.6

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Woody Code Snippets plugin (versions <= 2.4.5). Update the WordPress Woody Code Snippets plugin to the latest available version (at least 2.4.6).

Affected:
up to 2.4.6
Fixed in:
2.4.6
Disclosed:
Jun 14, 2022

Woody code snippets <= 2.4.5 - Reflected Cross-Site Scripting

medium

The Woody code snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 2.4.5
Fixed in:
2.4.6
Disclosed:
Jun 2, 2022

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.4.6

unknown

The Woody code snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

Affected:
up to 2.4.6
Fixed in:
2.4.6
Disclosed:
Jun 2, 2022

Woody code snippets <= 2.3.9 - Cross-Site Request Forgery Bypass

medium

The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated attackers to activate and deactivate snippets via a forged reque...

CVSS:
4.3
Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Sep 16, 2020

CVE-2020-36759 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.3.10

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Woody ad snippets plugin (versions <= 2.3.9).

Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Sep 16, 2020

Woody Ad Snippets <= 2.2.8 - Authenticated Cross-Site Scripting

medium

The insert-php (aka Woody ad snippets) plugin before 2.2.9 for WordPress allows authenticated XSS via the winp_item parameter.

CVSS:
6.4
Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Sep 13, 2019

CVE-2019-16289 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.2.9

unknown

[en] The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Sep 13, 2019

CVE-2019-16289 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.2.5

unknown

[en] admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Sep 3, 2019

CVE-2019-15858 on NVD →

Woody Ad Snippets <= 2.2.5 - Arbitrary Post Deletion

high

admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.

CVSS:
7.5
Affected:
up to 2.2.5
Fixed in:
2.2.6
Disclosed:
Aug 9, 2019

CVE-2019-14773 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.2.6

unknown

[en] admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.

Affected:
up to 2.2.6
Fixed in:
2.2.6
Disclosed:
Aug 8, 2019

CVE-2019-14773 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.2.5

unknown

Unauthenticated stored Cross-Site Scripting (XSS) vulnerability found by Jerome Bruandet (Nintechnet) by WordPress Woody Ad Snippets plugin (versions <= 2.2.4).

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Aug 6, 2019

Woody Ad Snippets <= 2.2.4 - Missing Authorization to Settings Import

high

admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.

CVSS:
8.8
Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Aug 2, 2019

CVE-2019-15858 on NVD →

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.3.10

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 2.3.10
Fixed in:
2.3.10

Woody code snippets &#8211; Insert Header Footer Code, AdSense Ads [insert-php] < 2.4.6

unknown

The plugin does not escape a generated URLs before outputting them back in an attribute, leading to Reflected Cross-Site Scripting

Affected:
up to 2.4.6
Fixed in:
2.4.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database