Two high-severity vulnerabilities have been disclosed in popular WordPress snippet-management plugins, exposing sites to remote code execution through CWE-94 code injection flaws. CVE-2026-25001 affects Post Snippets by Saad Iqbal in versions through 4.0.12, while CVE-2026-25366 affects Woody ad snippets (insert-php) by Themeisle in versions through 2.7.1. Both issues were documented with Patchstack references and indicate that attackers could inject or include malicious code on vulnerable WordPress installations.
The two CVEs differ in attack complexity but both carry severe impact to confidentiality, integrity, and availability. CVE-2026-25001 is scored with CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H, while CVE-2026-25366 carries CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, making the Woody ad snippets flaw easier to exploit once low privileges are obtained. Organizations running either plugin should identify affected versions, prioritize updates beyond the vulnerable releases, and review WordPress environments for signs of unauthorized code execution.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On March 25, 2026, both CVE-2026-25001 and CVE-2026-25366 records were updated to include CVSS v3.1 scoring, CWE-94 classification, and references to Patchstack advisories, adding technical severity and classification details.
A code injection vulnerability tracked as CVE-2026-25366 was documented for the Themeisle Woody ad snippets WordPress plugin (insert-php), affecting versions through 2.7.1 and presenting potential remote code execution impact.
A code injection vulnerability tracked as CVE-2026-25001 was documented for the WordPress Post Snippets plugin by Saad Iqbal, affecting versions through 4.0.12 and enabling remote code inclusion that could lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.