Query Shortcode WordPress Plugin Local File Inclusion Vulnerability

Vulnerability

A local file inclusion vulnerability has been identified in the Query Shortcode plugin for WordPress, affecting all versions up to and including 0.2.1. The vulnerability arises in the shortcode function, allowing authenticated attackers with contributor-level access and above to include and execute arbitrary .php files on the server. This exploitation could bypass access controls, access sensitive data, or execute code in cases where .php files can be uploaded and included.

Impact

Exploitation of this vulnerability could lead to unauthorized file inclusion, allowing execution of malicious PHP code on the server.

Remediation

No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: May 27, 2026, 7:19 AM
Updated: May 27, 2026, 7:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.3
remediation
0.0
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.