Known vulnerabilities in Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts
Insert PHP, JavaScript, CSS, HTML, ads & tracking code into WordPress headers, footers, pages & content with conditional logic — no theme editing.
7Reported vulnerabilities
9.9Highest CVSS score
2.7.6Latest version
60,000+Active installs
What to do now
Update Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts to 3.3.1 or later.
7 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2019-14773 | High | 1.6% | 2.2.5 and earlier | 2.2.6 |
August 8, 2019 |
| CVE-2024-3105 | Critical | 2.8% | 0 to 2.5.0 (inclusive) 0 to 2.5.0 (inclusive) |
2.5.1 |
June 15, 2024 |
| CVE-2019-16289 | Medium | 1.0% | Before 2.2.8 | 2.2.8 |
September 13, 2019 |
| CVE-2017-20251 | Critical | 0.6% | 0 up to (but not including) 3.3.1 | 3.3.1 |
June 9, 2026 |
| CVE-2026-25366 | High | 0.3% | 2.7.1 and earlier | 2.7.2 |
March 23, 2026 |
| WF-95bae3f2-313b-4b6c-a81c-8af6f169151b | Medium | — | 2.4.5 and earlier | 2.4.6 |
June 2, 2022 |
| CVE-2024-35751 | Medium | 0.3% | 2.5.0 and earlier | 2.5.1 |
June 6, 2024 |