CVE · High

CVE-2026-8832 — WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.3.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8832 WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.3.6 Improper Control of Generation of Code ('Code Injection') High 8.8 < 2.3.6 2.3.6 2026-05-26

CVE-2026-8832

A vulnerability exists in WordPress plugins up to version 2.3.5 that permits unauthorized code execution. This flaw arises from the registration of a custom post type without adequate capability controls, allowing attackers with author-level access or higher to create and publish malicious PHP snippets via XML-RPC. These snippets are then executed by the server when rendered through a specific shortcode.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.