CVE-2024-3105: Themeisle Woody Code Snippets – Insert Php, Css, Js, And Header/footer Scripts
Critical severity, CVSS 9.9. EPSS: 2.8% chance of exploitation in the next 30 days.
The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server.
Affected products
- Themeisle Woody Code Snippets – Insert Php, Css, Js, And Header/footer Scripts: up to and including 2.5.0
- Webcraftic Woody Ad Snippets: up to and including 2.5.0
Published 2024-06-15. Last modified 2026-06-17.