CVE-2024-13900: Satollo Head, Footer, And Post Injections
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.
Affected products
- Satollo Head, Footer, And Post Injections: before 3.3.1 (fixed in 3.3.1)
Published 2025-02-21. Last modified 2026-06-17.