Vulnerabilities / WPCode / WPSEC-2026-0695

WPCode <= 2.3.9 - Unauthenticated Snippet Execution Bypass via 'wpcode-safe-mode' Parameter

Medium 5.3 CWE-863Fixed in 2.4.0
ID
WPSEC-2026-0695
Plugin
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager (insert-headers-and-footers)
Affected
all versions before 2.4.0
Remediation
Update to 2.4.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-863
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
Attack surface
WPCode on WPSec AttackSurface
Fix released
Published

Description

The WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager plugin for WordPress is vulnerable to unauthorized safe mode activation via the 'wpcode-safe-mode' parameter in all versions up to, and including, 2.3.9, due to an insufficient authorization check. The plugin enables safe mode for any request whose URI contains the login page filename, and it matches that filename anywhere in the URI, including the query string. This makes it possible for unauthenticated attackers to stop auto-inserted code snippets from running on their own requests, bypassing any security, redirect or access-control logic the site implements through those snippets.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0