Shortcode Cleaner Lite Missing Authorization Vulnerability in WordPress

Vulnerability

A vulnerability exists in the Shortcode Cleaner Lite plugin for WordPress, affecting all versions through 1.0.9. The issue arises from a lack of proper capability checks in the download_backup() function, allowing authenticated attackers with Subscriber-level access or higher to export arbitrary options. This unauthorized data access could lead to exposure of sensitive information or options that could be manipulated.

Impact

Exploitation of this vulnerability could result in unauthorized access to and export of arbitrary options, potentially leading to exposure or manipulation of sensitive data.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.9
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.