WordPress Head, Footer and Post Injections Plugin PHP Code Injection Vulnerability

Vulnerability

A PHP code injection vulnerability exists in the Head, Footer and Post Injections plugin for WordPress, affecting all versions through 3.3.0. This vulnerability allows authenticated attackers with Administrator-level access to inject PHP code in multisite environments.

Impact

Exploitation of this vulnerability could lead to unauthorized PHP code execution on the server.

Remediation

Users are advised to update the Head, Footer and Post Injections plugin to version 3.3.1 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.5
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.