CVE-2025-24621: WordPress Arconix Shortcodes plugin <= 2.1.15 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.15.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Reflected XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.15.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24621?
CVE-2025-24621 is classified as a reflected cross-site scripting (XSS) vulnerability, which can potentially allow attackers to execute scripts in the context of a user's session.
How do I fix CVE-2025-24621?
To fix CVE-2025-24621, update the Arconix Shortcodes plugin to version 2.1.16 or later.
What versions of Arconix Shortcodes are affected by CVE-2025-24621?
CVE-2025-24621 affects Arconix Shortcodes versions from n/a through 2.1.15.
What type of attack does CVE-2025-24621 facilitate?
CVE-2025-24621 facilitates reflected XSS attacks, which can expose user data to attackers.
Who is impacted by CVE-2025-24621?
Users of the Arconix Shortcodes plugin for WordPress prior to version 2.1.16 are impacted by CVE-2025-24621.