Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A flaw disclosed in January 2020 let an attacker potentially run malicious code through the Code Snippets WordPress plugin—but only by tricking a logged-in site administrator into making a forged request. Wordfence reported that versions through 2.13.3 were vulnerable; version 2.14.0 fixed that specific issue. Those are historical version numbers: install the latest version available from WordPress, not merely the old patch.

What was the Code Snippets vulnerability?

The incident was CVE-2020-8417, a cross-site request forgery (CSRF) flaw in the plugin’s snippet-import function that could lead to remote code execution (RCE). Wordfence rated it 8.8 (High) on the CVSS scale in its January 28, 2020 disclosure. The vulnerable versions were Code Snippets through 2.13.3, and the developer fixed the issue in version 2.14.0. Wordfence’s disclosure gives the technical details and timeline.

Wordfence said the plugin was installed on more than 200,000 sites when it reported the flaw. That figure describes installations at the time; it is not a count of sites that were still vulnerable or successfully attacked.

How could an attacker exploit it?

The import function did not have the CSRF protection used by nearly all the plugin’s other endpoints. An attacker could exploit that gap by inducing an administrator who was logged in to visit a malicious page or follow a link that sent a forged request to the WordPress site.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Imported snippets were supposed to be disabled by default. Wordfence found that an attacker could set an active flag in the JSON import data, causing the malicious snippet to run instead. Depending on the code, the potential consequences included taking over the site, disclosing information, creating an administrator account, or infecting site visitors.

  • A logged-in administrator was required: the request depended on an administrator’s active authenticated session.
  • The administrator had to be induced to visit or follow something malicious: this was not simply an unauthenticated stranger executing code with no user interaction.
  • Comments did not have to be enabled: Wordfence said a malicious page visit while the administrator was logged in could be enough; the site’s comment setting was irrelevant.

Which versions were affected, and what fixed the 2020 issue?

Question Answer
Vulnerable range Code Snippets versions through 2.13.3, according to Wordfence’s January 2020 disclosure.
Historical fix Version 2.14.0 fixed CVE-2020-8417.
What to install now The latest version available through WordPress or the official plugin source. WordPress.org listed version 3.10.2, dated September 1, 2026, when accessed for this article; check the official plugin listing for the current release and changelog.

Version 2.14.0 is the historical fix for this particular vulnerability, not a current update recommendation. Updating directly to the latest available release is the practical way to get subsequent security fixes as well.

How to update Code Snippets

  1. Sign in to your WordPress dashboard and open Plugins > Installed Plugins.
  2. Find Code Snippets. If WordPress offers an update, select Update now and wait for the update to complete.
  3. If no update is offered, check the plugin’s official WordPress.org listing for the latest release, then follow WordPress’s normal plugin update process.
  4. After updating, confirm the installed version on the Plugins page. If the site still runs a release older than 2.14.0, update it before relying on the fix for CVE-2020-8417.

An update addresses the vulnerable plugin code; it does not establish whether a site was previously compromised. The cited sources do not quantify successful exploitation of CVE-2020-8417 or identify how many sites remain on vulnerable releases. If there are signs of an incident, treat that as a separate site-security investigation rather than assuming an update alone proves the site is clean.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How CVE-2020-8417 differs from later plugin issues

Code Snippets has had separate vulnerabilities since the 2020 incident. Patchstack lists CVE-2025-13035 as affecting versions through 3.9.1, fixed in 3.9.2, and CVE-2026-1785 as affecting versions through 3.9.4, fixed in 3.9.5. These are distinct advisories, not later names for CVE-2020-8417. See the individual CVE-2025-13035 entry and CVE-2026-1785 entry for their affected ranges and fixes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.