Back

HIGH

ORDER POST <= 2.0.2 - Unauthenticated Arbitrary Shortcode Execution

Published Apr 10, 2025

Description

The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Wordfence
Published Apr 10, 2025
Updated Apr 8, 2026
Reserved Mar 25, 2025

CISA Vulnrichment

Updated Apr 10, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Wordfence
Published Apr 10, 2025
Updated Apr 8, 2026

GitHub

No data