Head Meta Data

Head Meta Data has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for Head Meta Data has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Head Meta Data is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Head Meta Data vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-0608

Head Meta Data <= 20251118 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta

Read the full analysis

Vulnerability Records

2 records
Head Meta Data banner
Latestv20260810

Head Meta Data

Jeff Starr

Author

Jeff Starr

4.8(19)
96/100
Last Updated
2026-08-10 (1mo ago)
Active Installs
10,000+
Downloads
493,589
Requires WP
4.7+
Requires PHP
5.6.20+
Tested up to
WP 7.1
Created
2012-11-14 (14y ago)

✨ Add meta tags to your site ✨ Blazing fast performance ✨ Uses only 60KB of code! Head Meta Data (HMD) improves the definition and semantic quality of your website by adding <meta> tags to the <head> section of your web pages. Super lightweight, fast, and user-friendly. 🤖 Default Meta Tags Customize the perfect set of meta tags for your site. For example: <head> <meta charset="utf-8"> <meta name="abstract" content="Obsessive Web Development"> <meta name="author" content="Jeff Starr (aka Perishable)"> <meta name="classification" content="Website Development"> <meta name="copyright" content="Copyright Perishable Press"> <meta name="description" content="Web Development Tutorials"> <meta name="designer" content="Jeff Starr @ Monzilla Media"> <meta name="distribution" content="Global"> <meta name="keywords" content="Web, WordPress, Tutorials"> <meta name="language" content="en"> <meta name="publisher" content="Perishable Press"> <meta name="rating" content="General"> <meta name="resource-type" content="Document"> <meta name="revisit-after" content="3"> <meta name="subject" content="Web Dev + WordPress + Security"> <meta name="template" content="shapeSpace WordPress Theme"> <meta name="robots" content="index,follow"> <!-- plus you can add your own custom tags! --> </head> 🤖 Dynamic Meta Tags Use shortcodes to dynamically output SEO meta tags: <title>[hmd_post_title] | My Awesome Website</title> <meta name="description" content="[hmd_post_excerpt]"> This outputs dynamic titles and descriptions, useful for SEO. You also can add unique meta tags and markup on specific posts and pages. Check out the Installation tab for more information. ✨ Help bots understand your content better 🤖 Features Simple and easy to use Clean, standards-based code Customize all <meta> tags Add your own custom <meta> tags Add custom meta tags on any post or page Supports X (Twitter) Cards and Facebook Open Graph tags Supports <meta>, <link>, <base>, <title>, and <style> Automatically adds tags to the <head> section of all pages Check out a Live Preview of your meta tags and custom tags Auto-populates tags using your site’s information Use shortcodes to include dynamic information Easily disable any unwanted tags Lightweight, fast, and secure ✨ Check out Head Meta Pro to define tags for each page view 🤖 Shortcodes Shortcodes enable you to include dynamic bits of information in your meta tags. Head Meta Data provides the following shortcodes: [hmd_post_excerpt] Outputs post excerpt [hmd_post_date] Outputs post date [hmd_post_author] Outputs post author [hmd_post_title] Outputs post title [hmd_post_cats] Outputs post categories [hmd_post_tags] Outputs post tags [hmd_site_tagline] Outputs site tagline [hmd_site_title] Outputs site title [hmd_year] Outputs current year [hmd_tab] Outputs tab space to tag markup So you can display your own set of custom meta tags exactly as desired. Learn more &raquo; 🤖 Pro Features The Pro version can do everything the free version can do, PLUS: Define meta tags for Custom Post Types Define meta tags for each type of page-view (e.g., home, posts, pages, archive, search) Define tags for Facebook (Open Graph) Define tags for X (Twitter) Define Facebook and X tags for each type of page view 40+ advanced shortcut variables like %POST_AUTHOR% and %ARCHIVE_TYPE% Dedicated “Meta Tags” meta box for posts and pages Add custom meta tags to any post or page-view Add custom script and style to any post or page-view Meta Tags box integrates with SEO plugins Additional meta tags beyond the free version Dedicated setting for image_src link tag Premium support for pro purchases ✨ Level up your meta tags with Head Meta Pro &raquo; 🤖 Privacy This plugin does not collect or store any user data. It does not set any cookies, and it does not connect to any third-party locations. Thus, this plugin does not affect user privacy in any way. Head Meta Data is developed and maintained by Jeff Starr, 15-year WordPress developer and book author. 🤖 Support Development I develop and maintain this free plugin with love for the WordPress community. To show support, you can make a donation or purchase one of my books: The Tao of WordPress Digging into WordPress .htaccess made easy WordPress Themes In Depth Wizard’s SQL Recipes for WordPress And/or purchase one of my premium WordPress plugins: BBQ Pro – Blazing fast WordPress firewall Blackhole Pro – Automatically block bad bots Banhammer Pro – Monitor traffic and ban the bad guys GA Google Analytics Pro – Connect WordPress to Google Analytics Head Meta Pro – Ultimate Meta Tags for WordPress REST Pro Tools – Awesome tools for managing the WP REST API Simple Ajax Chat Pro – Unlimited chat rooms USP Pro – Unlimited front-end forms Links, tweets and likes also appreciated. Thanks! 🙂

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C