CVE-2026-2305Disclosure

LOWCVSS 6.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `aFhfc_footer_code` post meta values in all versions up to, and including, 2.3. This is due to the plugin outputting these meta values without any sanitization or escaping. While the plugin restricts its own metabox and save handler to administrators via `current_user_can('manage_options')`, it does not use `register_meta()` with an `auth_callback` to protect these meta keys. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts via the WordPress Custom Fields interface that execute when an administrator previews or views the post.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-10); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-19: 1Exploit Tool / Code · 2026-04-19: 1Technical Details · 2026-04-10: 304-1004-1104-19
Signal classification3 categories
Disclosure
360.0%
General
120.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-103
Disclosure3
2026-04-111
General1
2026-04-191
PoC1
Full discourse5 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-2305-addfunc-head-footer-code-version-2-3-medium-vulnerability-proof-of-concept CVE-2026-2305 #WordPress plugin #vulnerability addfunc-head-footer-code #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post links to a proof‑of‑concept for CVE‑2026‑2305, presenting code that demonstrates the vulnerability, but it does not mention active exploitation, patches, or false positives.

    0000042
    6 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-2305 📊 Severity: 6.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2305 #CVE-2026-2305 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/c6mnPyfymU

    Post summary

    A medium‑severity CVE affecting WordPress has been announced with a reference to the NVD page, but no technical details, PoC, exploit code, active exploitation, or patch information were included.

    0000032
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2305 The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `aFhfc_footer_code` p… https://www.cve.org/CVERecord?id=CVE-2026-2305

    Post summary

    The statement reports a new WordPress plugin vulnerability (CVE‑2026‑2305) that is a stored XSS affecting specific code fields, but provides no PoC, exploit, patch, or active exploitation evidence.

    0000098
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2305 Stored Cross-Site Scripting in AddFunc Head & Footer Code Plugin for WordPress 2.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2305

    Post summary

    The entry announces a stored XSS vulnerability (CVE-2026-2305) affecting the AddFunc Head & Footer Code plugin for WordPress 2.3.

    0000037
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2305 - AddFunc Head & Footer Code <= 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields Intel Report: https://ift.tt/rPTdCDf

    Post summary

    The message alerts to CVE-2026-2305, a stored XSS vulnerability in AddFunc Head & Footer Code versions ≤2.3 affecting Contributor+ users via custom fields, and links to an Intel Report for details.

    0000033
    280 followersView on X

Explore more