Shortcode Cleaner Lite Missing Authorization Vulnerability in WordPress
Vulnerability
A vulnerability exists in the Shortcode Cleaner Lite plugin for WordPress, affecting all versions through 1.0.9. The issue arises from a lack of proper capability checks in the download_backup() function, allowing authenticated attackers with Subscriber-level access or higher to export arbitrary options. This unauthorized data access could lead to exposure of sensitive information or options that could be manipulated.
Impact
Exploitation of this vulnerability could result in unauthorized access to and export of arbitrary options, potentially leading to exposure or manipulation of sensitive data.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
5.9remediation
0.0relevance
0.0threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
