CVE-2025-47673: WordPress Arconix Shortcodes plugin <= 2.1.16 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.16.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Reflected XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.16.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47673?
The CVE-2025-47673 vulnerability is classified as a high severity reflected Cross-site Scripting (XSS) issue.
How do I fix CVE-2025-47673?
To fix CVE-2025-47673, upgrade the Arconix Shortcodes plugin to version 2.1.17 or later.
What systems are affected by CVE-2025-47673?
CVE-2025-47673 affects all versions of Arconix Shortcodes from n/a up to and including version 2.1.16.
What type of vulnerability is CVE-2025-47673?
CVE-2025-47673 is an improper neutralization of input during web page generation leading to reflected Cross-site Scripting (XSS).
Can CVE-2025-47673 lead to security breaches?
Yes, CVE-2025-47673 can lead to security breaches through exploitation of reflected XSS, allowing attackers to execute scripts in the context of the user's browser.