← back to popular plugins
wordfence / plugin · insert-php

Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts

insert-php
total installs
60,000
total vulns
1
critical
0
high
1
medium
0
low
0
latest vuln
patched
1
unpatched
0
avg time to patch
vulnerabilities (1)
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts <= 2.7.1 - Authenticated (Contributor+) Remote Code Execution
high ✓ patched
cvss score 8.8
cwe CWE-94: Improper Control of Generation of Code ('Code Injection')
published Mar 23, 2026
The Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.