Unauthorized Data Modification in Insert Headers and Footers Code Plugin for WordPress
CVE-2025-2779

6.5MEDIUM

What is CVE-2025-2779?

The Insert Headers and Footers Code – HT Script plugin for WordPress is susceptible to unauthorized data modification due to a lack of proper capability checks in the ajax_dismiss function. This vulnerability enables authenticated attackers, holding at least Subscriber-level access, to alter option values to 1/true on affected WordPress sites. Such alterations could potentially disrupt site functionality, resulting in access denial for legitimate users and altering key operational settings, including user registrations.

Affected Version(s)

Insert Headers and Footers Code – HT Script * <= 1.1.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.