Uncode Core <= 2.9.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
medium
The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and 'uncode_text_icon' shortcodes in all versions up to, and including, 2.9.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- CVSS:
- 6.4
- Affected:
- up to 2.9.4.2
- Fixed in:
- 2.9.4.3
- Disclosed:
- Jul 3, 2025
CVE-2025-6944 on NVD →
Uncode Core <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary Shortcode Execution in uncode_get_medias
medium
The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.3
- Affected:
- up to 2.9.1.6
- Fixed in:
- 2.9.1.7
- Disclosed:
- Feb 17, 2025
CVE-2024-13689 on NVD →
Uncode Core <= 2.8.8 - Privilege Escalation
high
The Uncode Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.8.8. This makes it possible for subscribers to escalate their privileges to those of a higher level account.
- CVSS:
- 8.8
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.9
- Disclosed:
- Dec 21, 2023
CVE-2023-51515 on NVD →
Uncode Core <= 2.8.8 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The uncode-core plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers with subscriber level access or higher to delete arbitrary files on the site.
- CVSS:
- 8.1
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.9
- Disclosed:
- Dec 21, 2023
CVE-2023-51500 on NVD →
Uncode Core <= 2.8.6 - Reflected Cross-Site Scripting
medium
The uncode-core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.7
- Disclosed:
- Dec 21, 2023
CVE-2023-51501 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database