HIGH
Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution
Published Jul 8, 2025
7.3
HIGHCVSS 3.1
EPSS 0.45%
Description
The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_get_products_shortcode() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected products
-
- Version 0StatusaffectedConstraints<=8.2.3
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jul 8, 2025
Updated Apr 8, 2026
Reserved Jun 26, 2025
Link CVE-2025-6744
CISA Vulnrichment
Updated Jul 8, 2025
ENISA EUVD
EUVD-2025-20414 Assigner Wordfence
Published Jul 8, 2025
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2025-20414