← WordPress Vulnerabilities
WordPress security by component

Head, Footer and Post Injections

Head, Footer and Post Injections is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Feb 21, 2025; the highest CVE/CNA score is 4.1.

Plugin slug: head-footer-and-post-injections

CVE-2024-13900: Head, Footer and Post Injections: Code execution

Head, Footer and Post Injections is affected by code execution. Exploitation requires at least administrator-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.

PublishedFeb 21, 2025
Safe version guidanceSee mitigation notes
Safe version
Feb 21, 2025 CVE-2024-13900
Head, Footer and Post Injections: Code execution
Head, Footer and Post Injections is affected by code execution. Exploitation requires at least administrator-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE4.1
NVD7.2