The Woody code snippets plugin for WordPress, which allows users to insert code into their website’s header and footer, has a security vulnerability. This vulnerability, which exists in all versions up to 2.5.0, allows attackers with contributor-level access or higher to execute code on the server. This is a serious issue as the plugin does not limit the use of this feature to authorized users with high-level access.