LuckyWP Scripts Control

LuckyWP Scripts Control has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.4 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for LuckyWP Scripts Control has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. LuckyWP Scripts Control is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
4.8/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all LuckyWP Scripts Control vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.4CVE-2023-29239

LuckyWP Scripts Control <= 1.2.1 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

2 records
LuckyWP Scripts Control banner
Latestv1.2.5

LuckyWP Scripts Control

LuckyWP

Author

LuckyWP

4.8(39)
96/100
Last Updated
2025-06-09 (1y ago)
Active Installs
3,000+
Downloads
35,556
Requires WP
4.7+
Requires PHP
5.6.20+
Tested up to
WP 6.8.8
Created
2018-10-10 (8y ago)

The “LuckyWP Scripts Control” plugin allows you to insert and manage custom code into website. For example, you can insert Google Analytics code, Google Search Console verification meta tag, Facebook pixel, custom CSS/JS and other code without edit theme files. Features Great user interface: simple and functionally. Insert code before </head>, after <body> or before </body>. Items sortable. Add Google Analytics code. Add Google Verification meta tag. Add Google Tag Manager code. Add Facebook pixel code. Add custom meta tags. Add custom JS/CSS/HTML code. RTL support.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C