WPCode <= 2.3.9 - Unauthenticated Snippet Execution Bypass via 'wpcode-safe-mode' Parameter
- ID
- WPSEC-2026-0695
- Plugin
- WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager (insert-headers-and-footers)
- Affected
- all versions before 2.4.0
- Remediation
- Update to 2.4.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-863
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
- Attack surface
- WPCode on WPSec AttackSurface
- Fix released
- Published
Description
The WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager plugin for WordPress is vulnerable to unauthorized safe mode activation via the 'wpcode-safe-mode' parameter in all versions up to, and including, 2.3.9, due to an insufficient authorization check. The plugin enables safe mode for any request whose URI contains the login page filename, and it matches that filename anywhere in the URI, including the query string. This makes it possible for unauthenticated attackers to stop auto-inserted code snippets from running on their own requests, bypassing any security, redirect or access-control logic the site implements through those snippets.
References
- https://wpsec.com/vuln/WPSEC-2026-0695/
- https://plugins.svn.wordpress.org/insert-headers-and-footers/tags/2.4.0/
- https://wordpress.org/plugins/insert-headers-and-footers/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS