← WordPress Vulnerabilities
WordPress security by component

Insert Headers and Footers Code – HT Script

Insert Headers and Footers Code – HT Script is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: insert-headers-and-footers-script

CVE-2026-66474: HT Script permits cross-site request forgery against an undisclosed operation

Insert Headers and Footers Code – HT Script through 1.1.8 does not adequately verify that an undisclosed state-changing request was intentionally made by the logged-in victim. An unauthenticated attacker can cause a privileged user's browser to submit that request. The Patchstack CNA record does not disclose the endpoint, action, nonce failure, parameters or resulting state change.

PublishedJul 27, 2026
Safe version guidanceSee mitigation notes
Safe version
Jul 27, 2026 CVE-2026-66474
HT Script permits cross-site request forgery against an undisclosed operation
Insert Headers and Footers Code – HT Script through 1.1.8 does not adequately verify that an undisclosed state-changing request was intentionally made by the logged-in victim. An unauthenticated attacker can cause a privileged user's browser to submit that request. The Patchstack CNA record does not disclose the endpoint, action, nonce failure, parameters or resulting state change.
See mitigation notes
CVE4.3
NVDPending
Apr 02, 2025 CVE-2025-2779
Insert Headers and Footers Code – HT Script: A security weakness
Insert Headers and Footers Code – HT Script is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending