Uncode Core WordPress Plugin Shortcode Execution Vulnerability

Vulnerability

A vulnerability allowing authenticated users with Subscriber-level access and above to execute arbitrary shortcodes has been identified in the Uncode Core plugin for WordPress. This issue is present in all versions through 2.9.1.6. The vulnerability arises because the plugin does not properly validate values before executing them as shortcodes, allowing for unauthorized shortcode execution.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of shortcodes, potentially allowing attackers to inject malicious code or manipulate site content.

Remediation

Users are advised to update the Uncode Core plugin to version 2.9.1.7 or a newer patched version.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.3
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.