azurecurve Shortcodes in Comments WordPress Plugin Arbitrary Shortcode Execution Vulnerability
Vulnerability
A vulnerability allowing arbitrary shortcode execution has been identified in the azurecurve Shortcodes in Comments plugin for WordPress, affecting all versions through 2.0.2. The issue arises because the plugin does not properly validate values before executing shortcodes, allowing unauthenticated attackers to execute arbitrary shortcodes.
Impact
Exploitation of this vulnerability allows for arbitrary shortcode execution, which could be used to execute potentially harmful actions or scripts on the WordPress site.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
8.1remediation
0.0relevance
0.0threat
3.2urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
