Impact
An unauthenticated Cross Site Request Forgery flaw exists in the Insert Headers and Footers Code – HT Script plugin versions up to and including 1.1.8. The flaw allows an attacker to forge requests that cause logged‑in users, such as administrators, to submit configuration changes to the plugin without the user’s explicit intent. If exploited, the attacker can insert malicious scripts into the header or footer that will run in the browsers of all site visitors, creating a vector for further exploitation such as phishing or credential theft.
Affected Systems
The vulnerability affects the WordPress plugin HT Plugins:Insert Headers and Footers Code – HT Script, specifically all releases with version 1.1.8 or earlier. No other WordPress or third‑party products are listed as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate level of severity. The EPSS score of < 1%, combined with the fact that it is not listed in the CISA KEV catalog, suggests that it is not widely exploited yet. The attack would require the attacker to persuade or trick a logged‑in administrator to submit a crafted request into the vulnerable plugin; however, because the vulnerability is unauthenticated, any user with sufficient privileges in the WordPress admin can be targeted. Attackers can potentially introduce persistent malicious code via the header/footer fields, leading to broad impact on site visitors.
OpenCVE Enrichment