Impact
The WP Shortcodes Plugin – Shortcodes Ultimate suffers from a missing or incorrect nonce check on its preview function. This flaw enables an unauthenticated attacker to craft a forged request that an administrator might click, causing the site to execute any shortcode the attacker supplies. In combination with the related CVE‑2025‑7354, the vulnerability also permits reflected cross‑site scripting. The weakness is a classic Cross‑Site Request Forgery problem (CWE‑352).
Affected Systems
WordPress sites installing Shortcodes Ultimate versions up to and including 7.4.2 are affected. The vulnerability is present in all builds of the plugin before the latest release that addresses the nonce validation bug. Site administrators using older plugin versions must be aware that any recruited admin click can trigger code execution.
Risk and Exploitability
The CVSS score of 6.1 marks the issue as moderate severity. With an EPSS score of less than 1 % the probability of an immediate exploit is low, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to lure a privileged user to click a crafted link, meaning that while the impact could be severe, the exploitation vector requires user interaction and is limited to sites with the vulnerable plugin installed.
OpenCVE Enrichment
EUVD