Shortcodes by United Themes WordPress Plugin Unauthenticated Arbitrary Shortcode Execution Vulnerability
Vulnerability
A vulnerability allowing unauthenticated arbitrary shortcode execution has been identified in the Shortcodes by United Themes plugin for WordPress, affecting all versions through 5.1.6. The issue arises because the plugin does not properly validate values before executing them with the do_shortcode function, allowing attackers to execute arbitrary shortcodes.
Impact
Exploitation of this vulnerability allows for unauthorized execution of shortcodes, which could lead to various impacts depending on the executed shortcode.
Remediation
Users are advised to update the Shortcodes by United Themes WordPress plugin to version 5.1.7 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
