What the vulnerability does
01Description
The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.
Explanation of Vulnerability in Simple Terms
02Summary
Head, Footer and Post Injections through version 3.3.0 contains a code injection vulnerability in how it processes injected content. An authenticated administrator with high privileges can inject malicious code that executes within the site. The vulnerability requires deliberate action by a high-privilege user and has limited impact on confidentiality, integrity, and availability.
What an attacker can do
03Attacker Capabilities
Inject and execute arbitrary code on the site if they have administrator-level access.
Potential impact on your site
04Site Impact
A malicious or compromised admin account can inject code affecting site content, data, or functionality.
Conditions required to exploit
05Prerequisites
Attacker must have high-privilege administrator credentials and network access to the site.
Key dates
06Disclosure timeline
February 21, 2025
CVE published
April 8, 2026
Record updated