Unauthorized Data Modification in Insert Headers and Footers Code Plugin for WordPress
CVE-2025-2779

6.5MEDIUM

What is CVE-2025-2779?

The Insert Headers and Footers Code – HT Script plugin for WordPress is susceptible to unauthorized data modification due to a lack of proper capability checks in the ajax_dismiss function. This vulnerability enables authenticated attackers, holding at least Subscriber-level access, to alter option values to 1/true on affected WordPress sites. Such alterations could potentially disrupt site functionality, resulting in access denial for legitimate users and altering key operational settings, including user registrations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Insert Headers and Footers Code – HT Script * <= 1.1.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.