PT-2026-31860 · WordPress · Addfunc Head & Footer Code

Published

2026-04-10

·

Updated

2026-04-19

·

CVE-2026-2305

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AddFunc Head & Footer Code plugin for WordPress versions prior to 2.3
Description The AddFunc Head & Footer Code plugin for WordPress is susceptible to Stored Cross-Site Scripting through the aFhfc head code, aFhfc body code, and aFhfc footer code post meta values. This occurs because the plugin outputs these meta values without proper sanitization or escaping. Although the plugin limits access to its metabox and save handler to administrators using current user can('manage options'), it does not employ register meta() with an auth callback to safeguard these meta keys. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts through the WordPress Custom Fields interface, which will execute when an administrator previews or views the post.
Recommendations For versions prior to 2.3, update to a newer version that contains a fix for this vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-2305

Affected Products

Addfunc Head & Footer Code