Arbitrary Shortcode Execution Vulnerability in Uncode Core Plugin for WordPress
CVE-2024-13689
6.3MEDIUM
What is CVE-2024-13689?
The Uncode Core plugin for WordPress contains a vulnerability that allows authenticated users, including those with Subscriber-level access, to execute arbitrary shortcodes due to improper validation of input values. This oversight enables potential attackers to run unwanted code, which can compromise site functionality and data integrity. All versions of the plugin up to and including 2.9.1.6 are affected, posing a significant risk to users relying on this plugin for their WordPress sites.
Affected Version(s)
Uncode Core * <= 2.9.1.6