Arbitrary Shortcode Execution Vulnerability in Uncode Core Plugin for WordPress
CVE-2024-13689
6.3MEDIUM
What is CVE-2024-13689?
The Uncode Core plugin for WordPress contains a vulnerability that allows authenticated users, including those with Subscriber-level access, to execute arbitrary shortcodes due to improper validation of input values. This oversight enables potential attackers to run unwanted code, which can compromise site functionality and data integrity. All versions of the plugin up to and including 2.9.1.6 are affected, posing a significant risk to users relying on this plugin for their WordPress sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Uncode Core * <= 2.9.1.6