Impact
The vulnerability is an improper control of code generation flaw that allows arbitrary code injection via the IF AS Shortcode plugin on WordPress sites. Because the plugin executes content without validating or sanitizing it, an attacker who can supply a malicious shortcode can run arbitrary code with the privileges of the WordPress process, effectively gaining full control of the affected server.
Affected Systems
WordPress sites that have installed the Mohammad I. Okfie IF AS Shortcode plugin in any released version up to and including 1.2 are affected. All sites with this plugin enabled are at risk, regardless of the server operating system or other plugins.
Risk and Exploitability
The CVSS score of 9.9 marks this vulnerability as critical. The EPSS score of less than 1% suggests it is not commonly exploited yet, but the impact remains severe. It is not listed in the CISA KEV catalog. Attackers would most likely exploit this by creating a crafted HTTP request that injects malicious code into a shortcode on a publicly accessible page or post. This inference is based on the described code injection mechanism, and no explicit attack vector was provided in the CVE data.
OpenCVE Enrichment