{
 "id": "WPSEC-2026-0695",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0695/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0695/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0695/index.md",
 "title": "WPCode <= 2.3.9 - Unauthenticated Snippet Execution Bypass via 'wpcode-safe-mode' Parameter",
 "description": "The WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager plugin for WordPress is vulnerable to unauthorized safe mode activation via the 'wpcode-safe-mode' parameter in all versions up to, and including, 2.3.9, due to an insufficient authorization check. The plugin enables safe mode for any request whose URI contains the login page filename, and it matches that filename anywhere in the URI, including the query string. This makes it possible for unauthenticated attackers to stop auto-inserted code snippets from running on their own requests, bypassing any security, redirect or access-control logic the site implements through those snippets.",
 "plugin": {
  "slug": "insert-headers-and-footers",
  "name": "WPCode",
  "full_name": "WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager",
  "wordpress_org": "https://wordpress.org/plugins/insert-headers-and-footers/",
  "advisories_url": "https://wpsec.com/vuln/plugin/insert-headers-and-footers/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/insert-headers-and-footers"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-863"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.4.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.4.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.4.0",
 "remediation": "Update to 2.4.0 or later.",
 "fix_released": "2026-10-08T12:13:30+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:07.235552+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0695/",
  "https://plugins.svn.wordpress.org/insert-headers-and-footers/tags/2.4.0/",
  "https://wordpress.org/plugins/insert-headers-and-footers/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/insert-headers-and-footers",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-10"
 }
}