PT-2025-13608 · WordPress · So-Called Air Quotes

Avraham Shemesh

·

Published

2025-03-29

·

Updated

2025-04-03

·

CVE-2025-2803

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions So-Called Air Quotes plugin for WordPress versions up to, and including, 0.1
Description The issue allows unauthenticated attackers to execute arbitrary shortcodes due to the software not properly validating a value before running do shortcode(). This enables the execution of an action that can lead to arbitrary shortcode execution.
Recommendations For So-Called Air Quotes plugin for WordPress versions up to, and including, 0.1, consider disabling the plugin until a patch is available to prevent arbitrary shortcode execution. Restrict access to the do shortcode() function to minimize the risk of exploitation. Avoid using shortcodes from untrusted sources in the affected plugin until the issue is resolved.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-2803

Affected Products

So-Called Air Quotes