WordPress security by component
Insert Headers and Footers Code – HT Script
Plugin description
Insert Headers and Footers Code – HT Script is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
insert-headers-and-footers-scriptLatest vulnerability
CVE-2026-66474: HT Script permits cross-site request forgery against an undisclosed operation
Insert Headers and Footers Code – HT Script through 1.1.8 does not adequately verify that an undisclosed state-changing request was intentionally made by the logged-in victim. An unauthenticated attacker can cause a privileged user's browser to submit that request. The Patchstack CNA record does not disclose the endpoint, action, nonce failure, parameters or resulting state change.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-66474
HT Script permits cross-site request forgery against an undisclosed operation
Insert Headers and Footers Code – HT Script through 1.1.8 does not adequately verify that an undisclosed state-changing request was intentionally made by the logged-in victim. An unauthenticated attacker can cause a privileged user's browser to submit that request. The Patchstack CNA record does not disclose the endpoint, action, nonce failure, parameters or resulting state change.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 02, 2025 |
CVE-2025-2779
Insert Headers and Footers Code – HT Script: A security weakness
Insert Headers and Footers Code – HT Script is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|