← Back to browse · API

CVE-2024-3105

Severity
CRITICAL
CVSS
9.9
EPSS
0.02778
Risk score
40.57
CISA KEV
No
PoC
No
Published
2024-06-15
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-31708, GHSA-VMQ4-67RJ-G3JW
Products
themeisle:Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts 0 ≤2.5.0
Sources
euvd EUVD-2024-31708

Description

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server.

References