Junglewise Threat Intelligence

CVE-2026-66474: HT Plugins Insert Headers and Footers Code CSRF

CVE-2026-66474 · Severity: medium · CVSS 4.3 · Published 2026-07-27

Executive brief

The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to a security flaw that could allow an attacker to trick a site administrator into performing unintended actions. By convincing an authorized user to click a malicious link or visit a specific webpage, an attacker could potentially modify site settings or inject unauthorized scripts. This could lead to unauthorized changes to the website's appearance or behavior without the administrator's direct consent.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the HT Plugins 'Insert Headers and Footers Code – HT Script' plugin for WordPress (versions <= 1.1.8). The vulnerability stems from a lack of proper nonce validation or equivalent CSRF protections within the plugin's administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it (e.g., via social engineering or a malicious link). Successful exploitation allows the attacker to perform unauthorized actions with the privileges of the victim, such as modifying header/footer scripts. As of the advisory date, no official patch has been released.

Affected products

  • HT Plugins Insert Headers and Footers Code – HT Script <= 1.1.8

Timeline

  • 2026-06-09: other: Reported by researcher Ananda Dhakal
  • 2026-07-27: disclosed: Advisory published by Patchstack
  • 2026-07-27: advisory: CVE record published to NVD dataset

References