REHub WordPress Theme Arbitrary Shortcode Execution Vulnerability
Vulnerability
A vulnerability allowing arbitrary shortcode execution has been identified in the REHub - Price Comparison, Multi Vendor Marketplace WordPress Theme, in all versions through 19.9.7. This issue arises because the theme does not properly validate user input before executing shortcodes, allowing unauthenticated users to execute arbitrary shortcodes on the site.
Impact
Exploitation of this vulnerability allows for arbitrary shortcode execution, which could be used to inject and execute malicious code or actions on the WordPress site.
Remediation
Users can update to version 19.9.8 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
