WordPress security by component
Header Footer Code Manager
Plugin description
Header Footer Code Manager manages custom code snippets inserted into website headers, footers, and selected content locations.
Header Footer Code Manager (header-footer-code-manager) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Oct 03, 2023; the highest published CVSS base score is 7.2.
Plugin slug:
header-footer-code-managerLatest vulnerability
CVE-2023-39989: Header Footer Code Manager: Cross-site request forgery
Header Footer Code Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
| Safe version |
|
||
|---|---|---|---|
| Oct 03, 2023 |
CVE-2023-39989
Header Footer Code Manager: Cross-site request forgery
Header Footer Code Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Jul 25, 2022 |
CVE-2022-0899
Header Footer Code Manager: Cross-site scripting
Header Footer Code Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Feb 24, 2022 |
CVE-2022-0710
Header Footer Code Manager: Cross-site scripting
Header Footer Code Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Nov 08, 2021 |
CVE-2021-24791
Header Footer Code Manager: SQL injection
Header Footer Code Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD7.2
|