CVE · Medium

CVE-2024-13900 — Head, Footer and Post Injections [header-footer] < 3.3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13900 Head, Footer and Post Injections [header-footer] < 3.3.1 Improper Control of Generation of Code ('Code Injection') Medium 4.1 < 3.3.1 3.3.1 2025-02-20

CVE-2024-13900

The Head, Footer and Post Injections plugin contains a PHP code injection vulnerability affecting versions 3.3.0 and earlier. Attackers with administrator privileges or higher can inject arbitrary PHP code, particularly in WordPress multisite installations. The vulnerability requires authenticated access at the administrator level or above to exploit. Versions 3.3.1 and later contain fixes for this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.