Cross-Site Request Forgery in WP Shortcodes Plugin by WordPress
CVE-2025-7369

6.1MEDIUM

What is CVE-2025-7369?

The WP Shortcodes Plugin, also known as Shortcodes Ultimate, contains a vulnerability due to inadequate nonce validation in its preview function. This allows unauthenticated attackers to forge requests to execute arbitrary shortcodes, posing significant risks if an administrator is tricked into executing an action. This vulnerability, when exploited alongside other issues, may lead to reflected Cross-Site Scripting attacks, further jeopardizing user security and site integrity.

Affected Version(s)

WP Shortcodes Plugin — Shortcodes Ultimate * <= 7.4.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.
CVE-2025-7369 : Cross-Site Request Forgery in WP Shortcodes Plugin by WordPress