Unauthorized Data Modification in Insert Headers and Footers Code Plugin for WordPress
CVE-2025-2779
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 April 2025
What is CVE-2025-2779?
The Insert Headers and Footers Code – HT Script plugin for WordPress is susceptible to unauthorized data modification due to a lack of proper capability checks in the ajax_dismiss function. This vulnerability enables authenticated attackers, holding at least Subscriber-level access, to alter option values to 1/true on affected WordPress sites. Such alterations could potentially disrupt site functionality, resulting in access denial for legitimate users and altering key operational settings, including user registrations.
Affected Version(s)
Insert Headers and Footers Code – HT Script * <= 1.1.2