Executive brief
The Header Footer Script Adder plugin for WordPress, which allows site owners to add custom code to their pages, contains a security flaw. This vulnerability allows users with author-level permissions or higher to inject malicious scripts into the website. These scripts will then run automatically in the browsers of any visitors who view the affected pages, potentially leading to unauthorized actions or data theft.
Technical details
The Header Footer Script Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'asm_code' Snippet Meta field. The root cause is a failure to properly sanitize user input and escape output in the 'pro/class-pro-admin.php' and 'pro/class-pro-public.php' files. An authenticated attacker with author-level privileges or higher can inject arbitrary web scripts into pages. These scripts execute in the context of a user's browser whenever they visit the compromised page. The vulnerability affects all versions up to and including 2.1.
Affected products
- mahethekiller Header Footer Script Adder – Insert Code in Header, Body & Footer Up to and including 2.1
Timeline
- 2026-07-23: disclosed: Vulnerability published by Wordfence and NVD.
References
- https://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-admin.php
- https://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-public.php
- https://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-public.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3611085%40header-and-footer-script-adder&new=3611085%40header-and-footer-script-adder
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c394c9bc-21f6-45ea-8eda-8ee22a9b87ba?source=cve