CVE Database /
CVE-2023-3524
CVE · Medium
CVE-2023-3524 — WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-3524
|
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.0.13.1
|
2.0.13.1 |
2023-07-17 |
—
|
CVE-2023-3524
The WPCode plugin for WordPress contained a cross-site scripting vulnerability that could be exploited to inject malicious code into websites, potentially leading to redirection, advertisement injection, and execution of arbitrary HTML when visitors access the site. This flaw affected versions before 2.0.13.1 and has been resolved in that release and later versions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings