CVE · Medium

CVE-2023-0328 — WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0328 WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.7 Incorrect Authorization Medium 4.3 < 2.0.7 2.0.7 2023-02-09

CVE-2023-0328

The WPCode plugin for WordPress through version 2.0.6 contains a capability check vulnerability in its ajax_auth_url, store_auth_key, and delete_auth functions that allows authenticated users with edit_posts permissions, such as contributors, to access and modify the authentication key for the WPCode library. This flaw enables unauthorized data access and modification by lower-privileged account holders.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.