LuckyWP Scripts Control
LuckyWP Scripts Control has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for LuckyWP Scripts Control has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. LuckyWP Scripts Control is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2023-29239LuckyWP Scripts Control <= 1.2.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

LuckyWP Scripts Control
Author
LuckyWP
The “LuckyWP Scripts Control” plugin allows you to insert and manage custom code into website. For example, you can insert Google Analytics code, Google Search Console verification meta tag, Facebook pixel, custom CSS/JS and other code without edit theme files. Features Great user interface: simple and functionally. Insert code before </head>, after <body> or before </body>. Items sortable. Add Google Analytics code. Add Google Verification meta tag. Add Google Tag Manager code. Add Facebook pixel code. Add custom meta tags. Add custom JS/CSS/HTML code. RTL support.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C