The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/changeset/3244016/ | Patch |
https://www.wordfence.com/threat-intel/vulnerabilities/id/5177bde6-4922-48ee-9155-577c392809a0?source=cve | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
25 Feb 2025, 04:02
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Satollo
Satollo head\, Footer\, And Post Injections |
|
References | () https://plugins.trac.wordpress.org/changeset/3244016/ - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/5177bde6-4922-48ee-9155-577c392809a0?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:satollo:head\,_footer\,_and_post_injections:*:*:*:*:*:wordpress:*:* |
21 Feb 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-21 12:15
Updated : 2025-02-25 04:02
NVD link : CVE-2024-13900
Mitre link : CVE-2024-13900
CVE.ORG link : CVE-2024-13900
JSON object : View
Products Affected
satollo
- head\,_footer\,_and_post_injections
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')