CVE-2025-6744: Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution
The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode through the woodmartgetproductsshortcode() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6744?
CVE-2025-6744 is considered a high severity vulnerability due to its potential for arbitrary shortcode execution.
How do I fix CVE-2025-6744?
To fix CVE-2025-6744, update the Woodmart theme for WordPress to version 8.2.4 or later.
Who is affected by CVE-2025-6744?
CVE-2025-6744 affects all users of the Woodmart theme for WordPress up to and including version 8.2.3.
What type of vulnerability is CVE-2025-6744?
CVE-2025-6744 is an arbitrary shortcode execution vulnerability.
What can happen if CVE-2025-6744 is exploited?
If successfully exploited, CVE-2025-6744 could allow attackers to execute malicious code within the WordPress site.