Code Snippets CPT WordPress Plugin Shortcode Execution Vulnerability

Vulnerability

A vulnerability allowing arbitrary shortcode execution has been identified in the Code Snippets CPT plugin for WordPress, affecting all versions through 2.1.0. The issue arises because the plugin permits users to execute actions without proper validation, allowing authenticated attackers with Subscriber-level access or higher to run arbitrary shortcodes.

Impact

Exploitation of this vulnerability allows for arbitrary shortcode execution, which could be used to execute potentially harmful actions or code within the WordPress environment.

Remediation

There is no known patch available for this vulnerability. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.9
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.