← WordPress Vulnerabilities
WordPress security by component

Header Footer Code Manager

Header Footer Code Manager is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Oct 03, 2023; the highest CVE/CNA score is 7.2.

Plugin slug: header-footer-code-manager

CVE-2023-39989: Header Footer Code Manager: Cross-site request forgery

Header Footer Code Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedOct 03, 2023
Safe version guidanceSee mitigation notes
Safe version
Oct 03, 2023 CVE-2023-39989
Header Footer Code Manager: Cross-site request forgery
Header Footer Code Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Jul 25, 2022 CVE-2022-0899
Header Footer Code Manager: Cross-site scripting
Header Footer Code Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Feb 24, 2022 CVE-2022-0710
Header Footer Code Manager: Cross-site scripting
Header Footer Code Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Nov 08, 2021 CVE-2021-24791
Header Footer Code Manager: SQL injection
Header Footer Code Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2