plugin

Uncode Core Vulnerabilities

5 known security issues reported for the Uncode Core WordPress plugin. Most recent disclosed Jul 3, 2025.

2 high 3 medium

Running Uncode Core on your site? Check whether your installed version is affected.

Scan your site free

Uncode Core <= 2.9.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes

medium

The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and 'uncode_text_icon' shortcodes in all versions up to, and including, 2.9.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...

CVSS:
6.4
Affected:
up to 2.9.4.2
Fixed in:
2.9.4.3
Disclosed:
Jul 3, 2025

CVE-2025-6944 on NVD →

Uncode Core <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary Shortcode Execution in uncode_get_medias

medium

The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with...

CVSS:
6.3
Affected:
up to 2.9.1.6
Fixed in:
2.9.1.7
Disclosed:
Feb 17, 2025

CVE-2024-13689 on NVD →

Uncode Core <= 2.8.8 - Privilege Escalation

high

The Uncode Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.8.8. This makes it possible for subscribers to escalate their privileges to those of a higher level account.

CVSS:
8.8
Affected:
up to 2.8.8
Fixed in:
2.8.9
Disclosed:
Dec 21, 2023

CVE-2023-51515 on NVD →

Uncode Core <= 2.8.8 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The uncode-core plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers with subscriber level access or higher to delete arbitrary files on the site.

CVSS:
8.1
Affected:
up to 2.8.8
Fixed in:
2.8.9
Disclosed:
Dec 21, 2023

CVE-2023-51500 on NVD →

Uncode Core <= 2.8.6 - Reflected Cross-Site Scripting

medium

The uncode-core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 2.8.6
Fixed in:
2.8.7
Disclosed:
Dec 21, 2023

CVE-2023-51501 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database