CVE · Medium

CVE-2023-3524 — WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3524 WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.0.13.1 2.0.13.1 2023-07-17

CVE-2023-3524

The WPCode plugin for WordPress contained a cross-site scripting vulnerability that could be exploited to inject malicious code into websites, potentially leading to redirection, advertisement injection, and execution of arbitrary HTML when visitors access the site. This flaw affected versions before 2.0.13.1 and has been resolved in that release and later versions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.