← back to popular plugins
wordfence / plugin · insert-php
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts
insert-php
total installs
60,000
total vulns
1
critical
0
high
1
medium
0
low
0
latest vuln
—
patched
1
unpatched
0
avg time to patch
—
vulnerabilities
(1)
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts <= 2.7.1 - Authenticated (Contributor+) Remote Code Execution
high
✓ patched
cve id
CVE-2026-25366 ↗
cvss score
8.8
cwe
CWE-94: Improper Control of Generation of Code ('Code Injection')
published
Mar 23, 2026
The Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.