Cross-Site Request Forgery in WP Shortcodes Plugin by WordPress
CVE-2025-7369
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 July 2025
What is CVE-2025-7369?
The WP Shortcodes Plugin, also known as Shortcodes Ultimate, contains a vulnerability due to inadequate nonce validation in its preview function. This allows unauthenticated attackers to forge requests to execute arbitrary shortcodes, posing significant risks if an administrator is tricked into executing an action. This vulnerability, when exploited alongside other issues, may lead to reflected Cross-Site Scripting attacks, further jeopardizing user security and site integrity.
Affected Version(s)
WP Shortcodes Plugin — Shortcodes Ultimate * <= 7.4.2