All 3 CVE vulnerabilities found in Insert Headers and Footers Code – HT Script, with AI-generated Chinese analysis, references, and POCs.
Vendor: htplugins
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-66474 | WordPress Insert Headers and Footers Code – HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 | 4.3 | Medium | 2026-07-27 |
| CVE-2025-12112 | Insert Headers and Footers Code – HT Script <= 1.1.6 - Authenticated (Author+) Stored Cross-Site Scripting CWE-79 | 6.4 | Medium | 2025-11-08 |
| CVE-2025-2779 | Insert Headers and Footers Code – HT Script <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update CWE-862 | 6.5 | Medium | 2025-04-02 |
All 3 known CVE vulnerabilities affecting Insert Headers and Footers Code – HT Script with full Chinese analysis, references, and POCs where available.