Uncode Core
cpe:2.3:a:undsgn:uncode:*:*:*:*:wordpress:*:*
- <= 2.9.1.6
A vulnerability allowing authenticated users with Subscriber-level access and above to execute arbitrary shortcodes has been identified in the Uncode Core plugin for WordPress. This issue is present in all versions through 2.9.1.6. The vulnerability arises because the plugin does not properly validate values before executing them as shortcodes, allowing for unauthorized shortcode execution.
Exploitation of this vulnerability could lead to unauthorized execution of shortcodes, potentially allowing attackers to inject malicious code or manipulate site content.
Users are advised to update the Uncode Core plugin to version 2.9.1.7 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.