PT-2026-32600 · Vendidero · Germanized For Woocommerce

Chiao-Lin Yu

·

Published

2026-04-14

·

Updated

2026-04-14

·

CVE-2026-2582

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-2582

Affected Products

Germanized For Woocommerce