First published: Sat Mar 29 2025(Updated: )
The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
So-Called Air Quotes | <=0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2803 is considered a high severity vulnerability due to its potential for arbitrary shortcode execution.
To fix CVE-2025-2803, update the So-Called Air Quotes plugin to the latest version beyond 0.1.
CVE-2025-2803 can facilitate attacks allowing unauthorized users to execute arbitrary code via shortcodes.
All users of the So-Called Air Quotes plugin for WordPress running version 0.1 or earlier are affected by CVE-2025-2803.
Yes, CVE-2025-2803 is relatively easy to exploit for attackers familiar with WordPress shortcode functionalities.