Arbitrary Shortcode Execution in Shortcodes by United Themes for WordPress
CVE-2024-13557
6.5MEDIUM
What is CVE-2024-13557?
The Shortcodes by United Themes plugin for WordPress contains a significant vulnerability allowing unauthenticated users to execute arbitrary shortcodes. This issue arises from inadequate validation of user input before invoking the do_shortcode function, posing a security risk for all versions up to and including 5.1.6. Attackers exploiting this flaw can execute harmful commands, potentially leading to unauthorized control over affected WordPress sites.
Affected Version(s)
Shortcodes by United Themes * <= 5.1.6