CVE-2025-6744: CWE-94 Improper Control of Generation of Code ('Code Injection') in xTemos Woodmart
The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_get_products_shortcode() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
CVE-2025-6744: CWE-94 Improper Control of Generation of Code ('Code Injection') in xTemos Woodmart
Description
The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_get_products_shortcode() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- Wordfence
- Date Reserved
- 2025-06-26T18:09:26.679Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 686ce78b6f40f0eb72f2e6c6
Added to database: 7/8/2025, 9:40:27 AM
Last updated: 7/8/2025, 9:40:27 AM
Views: 1
Related Threats
CVE-2025-7172: SQL Injection in code-projects Crime Reporting System
MediumCVE-2025-7171: SQL Injection in code-projects Crime Reporting System
MediumCVE-2025-7170: SQL Injection in code-projects Crime Reporting System
MediumCVE-2025-7169: SQL Injection in code-projects Crime Reporting System
MediumAbusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)
HighActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.