Impact
UIUX Lab Uix Shortcodes exposes a missing authorization flaw that permits attackers to inject and execute arbitrary shortcodes. This can lead to code execution or unintended content rendering, undermining the integrity of the site. The weakness is identified as a lack of proper access control (CWE‑862).
Affected Systems
The vulnerability affects the Uix Shortcodes plugin for WordPress from the earliest available build up to and including version 2.0.3. Any installation of the plugin within this range is potentially impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely. The flaw is not listed in CISA’s KEV catalog. Attackers would need to exploit the incorrect access control, likely via the plugin’s exposed interfaces; the precise attack vector is inferred as application‑level exploitation of the shortcode handler rather than remote code execution from the network layer.
OpenCVE Enrichment
EUVD