CVE-2026-2305 | addfunc AddFunc Head & Footer Code Plugin up to 2.3 on WordPress Custom Fields Interface register_meta aFhfc_head_code/aFhfc_body_code/aFhfc_footer_code cross site scripting
A vulnerability marked as problematic has been reported in addfunc AddFunc Head & Footer Code Plugin up to 2.3 on WordPress. This impacts the function register_meta of the component Custom Fields Interface. The manipulation of the argument aFhfc_head_code/aFhfc_body_code/aFhfc_footer_code leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-2305. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.