Input validation vulnerability in Header Footer Code Manager 1.1.35

The Header Footer Code Manager plugin for WordPress has a security vulnerability in versions 1.1.34 and earlier. This vulnerability allows unauthenticated attackers to activate, deactivate, and delete existing snippets without permission. It happens because the plugin does not have the right kind of security check called a “nonce validation” on the “process_bulk_action function”. This means that an attacker can trick a site administrator into performing an action, such as clicking on a link, and the attacker can take control of the plugin.

Detected in:

Header Footer Code Manager fixed vulnerable versions: >= * < 1.1.35

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.