Sniplets
Sniplets has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2008; all 3 are fixed as of September 2026. Their average CVSS score is 8.6, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 0 high. 2008 was the busiest year with 3 disclosures.
The most common weakness is Code Injection, behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, PHP Remote File Inclusion.
Every one of the 3 issues recorded for Sniplets has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by NBBN. Sniplets is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 2.9.2.
CVE-2008-1060Sniplets < 1.2.3 - Remote Code Execution
Read the full analysisVulnerability Records
Sniplets
Author
John Godley
Sniplets is a generic text insertion plugin with support for an extensible processing framework. At it’s simplest this means you can dynamically replace text in your posts with text that may be defined elsewhere, or created by some other module. For example, you can use Sniplets to perform syntax highlighting of files, execute custom PHP code, insert data from a database, and perform all manner of other useful tasks within a standard interface. Replace tags in a post with pre-defined text Apply processing functions to the pre-defined text to perform additional functionality Automatic insertion – data can be made to automatically appear in various places (header, footer, before post, after post, more tag, initialization) Custom processors can be written by the user Fully localized Sniplets is available in: English Belorussian thanks to Marcis Gasuns Documentation Full documentation can be found on the Sniplets page.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C