Arbitrary Shortcode Execution Vulnerability in Uncode Core Plugin for WordPress
CVE-2024-13689

6.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
18 February 2025

Summary

The Uncode Core plugin for WordPress contains a vulnerability that allows authenticated users, including those with Subscriber-level access, to execute arbitrary shortcodes due to improper validation of input values. This oversight enables potential attackers to run unwanted code, which can compromise site functionality and data integrity. All versions of the plugin up to and including 2.9.1.6 are affected, posing a significant risk to users relying on this plugin for their WordPress sites.

Affected Version(s)

Uncode Core * <= 2.9.1.6

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Mazzolini
.