Extension WordPress
Vulnérabilités Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts
Cette page rassemble les failles publiées pour Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts
8 fiches
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts <= 2.7.1 – Authenticated (Contributor+) Remote Code Execution
The Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level…
*-2.7.1
2.7.2
23/03/2026
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin…
*-2.5.0
2.5.1
14/06/2024
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output…
*-2.5.0
2.5.1
06/06/2024
Woody code snippets <= 2.4.5 – Reflected Cross-Site Scripting
The Woody code snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.4.5. This makes it possible for unauthenticated…
*-2.4.5
2.4.6
02/06/2022
Woody code snippets <= 2.3.9 – Cross-Site Request Forgery Bypass
The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for…
[*, 2.3.10)
2.3.10
16/09/2020
Woody Ad Snippets <= 2.2.8 – Authenticated Cross-Site Scripting
The insert-php (aka Woody ad snippets) plugin before 2.2.9 for WordPress allows authenticated XSS via the winp_item parameter.
[*, 2.2.9)
2.2.9
13/09/2019
Woody Ad Snippets <= 2.2.5 – Arbitrary Post Deletion
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.
*-2.2.5
2.2.6
09/08/2019
Woody Ad Snippets <= 2.2.4 – Missing Authorization to Settings Import
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
[*, 2.2.5)
2.2.5
02/08/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.