CVE-2024-13900 Information
Feb 22, 2025
cve
Description
The Head Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to and including 3.3.0. This makes it possible for authenticated attackers with Administrator-level access and above to inject PHP Code in multisite environments.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Reference
https://plugins.trac.wordpress.org/changeset/3244016/ https://www.wordfence.com/threat-intel/vulnerabilities/id/5177bde6-4922-48ee-9155-577c392809a0?source=cve
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
4.1
Share on: