Skip to main content

CVE-2025-6744: CWE-94 Improper Control of Generation of Code ('Code Injection') in xTemos Woodmart

High
VulnerabilityCVE-2025-6744cvecve-2025-6744cwe-94
Published: Tue Jul 08 2025 (07/08/2025, 09:22:30 UTC)
Source: CVE Database V5
Vendor/Project: xTemos
Product: Woodmart

Description

The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_get_products_shortcode() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Technical Details

Data Version
5.1
Assigner Short Name
Wordfence
Date Reserved
2025-06-26T18:09:26.679Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 686ce78b6f40f0eb72f2e6c6

Added to database: 7/8/2025, 9:40:27 AM

Last updated: 7/8/2025, 9:40:27 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats