Create Custom Forms for WordPress Smart Form Plugin Arbitrary Shortcode Execution Vulnerability
Vulnerability
A vulnerability allowing arbitrary shortcode execution has been identified in the 'Create custom forms for WordPress with a smart form plugin for smart businesses' plugin, in all versions through 1.2.4. The issue arises because the plugin does not properly validate values before executing them as shortcodes, allowing unauthenticated attackers to execute arbitrary shortcodes.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of shortcodes, which may allow attackers to execute malicious code or actions on behalf of the user.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
8.1remediation
0.0relevance
0.0threat
3.2urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
