Impact
The REHub theme allows any user to trigger the re_filterpost filter, which in turn calls WordPress’s do_shortcode function without properly validating the content of the shortcode string. This flaw permits the execution of any shortcode supplied by an attacker, which can lead to the execution of arbitrary PHP code on the host. The vulnerability exists in all releases of the theme up to and including version 19.9.7.
Affected Systems
All WordPress sites that use the sizam REHub – Price Comparison, Multi Vendor Marketplace Wordpress Theme in versions 19.9.7 or earlier are affected. The issue resides in the theme’s core files and does not require additional plugins or user privileges to exploit.
Risk and Exploitability
With a CVSS score of 7.3, the flaw is considered medium‑high severity, while an EPSS score of less than 1% indicates a low probability of current exploitation. The feature is not catalogued in CISA’s KEV list. An attacker does not need authentication; a crafted HTTP request containing the desired shortcode can be sent to any publicly accessible URL that processes the re_filterpost filter, enabling the attacker to run arbitrary PHP code.
OpenCVE Enrichment
EUVD