← WordPress Vulnerabilities
WordPress security by component

Woody Code Snippets

Woody Code Snippets is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jun 09, 2026; the highest CVE/CNA score is 9.9.

Plugin slug: insert-php

CVE-2017-20251: Woody Code Snippets: Code execution

Woody Code Snippets is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is < 3.3.1.

PublishedJun 09, 2026
Known safe version3.3.1
Safe version
Jun 09, 2026 CVE-2017-20251
Woody Code Snippets: Code execution
Woody Code Snippets is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is < 3.3.1.
3.3.1
CVE9.3
NVDPending
Mar 25, 2026 CVE-2026-25366
Woody ad snippets: Code execution
Woody ad snippets is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 2.7.1.
2.7.2
CVE9.9
NVDPending
Jun 15, 2024 CVE-2024-3105
Woody code snippets – Insert Header Footer Code, AdSense Ads: Code execution
Woody code snippets – Insert Header Footer Code, AdSense Ads is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.9
NVDPending
Jun 08, 2024 CVE-2024-35751
Woody ad snippets: Cross-site scripting
Woody ad snippets is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD4.8
Sep 13, 2019 CVE-2019-16289
Insert Php: Cross-site scripting
Insert Php is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 08, 2019 CVE-2019-14773
Insert Php: A security weakness
Insert Php is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5