Sniplets

Sniplets has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2008; all 3 are fixed as of September 2026. Their average CVSS score is 8.6, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 0 high. 2008 was the busiest year with 3 disclosures.

The most common weakness is Code Injection, behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, PHP Remote File Inclusion.

Every one of the 3 issues recorded for Sniplets has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by NBBN. Sniplets is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 2.9.2.

Strategic Overview

Avg CVSSHigh
8.6/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Sniplets vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2008-1060

Sniplets < 1.2.3 - Remote Code Execution

Read the full analysis

Vulnerability Records

3 records
Plugin Profile
Latestv1.4.5
2.8(4)
56/100
Last Updated
2012-04-29 (15y ago)
Active Installs
40+
Downloads
25,506
Requires WP
2.7+
Requires PHP
0+
Tested up to
WP 2.9.2
Created
2007-09-10 (19y ago)

Sniplets is a generic text insertion plugin with support for an extensible processing framework. At it’s simplest this means you can dynamically replace text in your posts with text that may be defined elsewhere, or created by some other module. For example, you can use Sniplets to perform syntax highlighting of files, execute custom PHP code, insert data from a database, and perform all manner of other useful tasks within a standard interface. Replace tags in a post with pre-defined text Apply processing functions to the pre-defined text to perform additional functionality Automatic insertion – data can be made to automatically appear in various places (header, footer, before post, after post, more tag, initialization) Custom processors can be written by the user Fully localized Sniplets is available in: English Belorussian thanks to Marcis Gasuns Documentation Full documentation can be found on the Sniplets page.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C