Skip to main content

CVE-2025-6944: Uncode Core WordPress Plugin XSS Vulnerability

CVE-2025-6944 is a stored XSS vulnerability in the Uncode Core WordPress plugin affecting shortcodes in versions up to 2.9.4.2. Attackers with contributor-level access can inject malicious scripts. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2025-6944 Overview

The Uncode Core plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in the uncode_hl_text and uncode_text_icon shortcodes. The flaw affects all plugin versions up to and including 2.9.4.2. The plugin fails to properly sanitize user-supplied shortcode attributes and does not escape output. Authenticated attackers with contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any visitor accessing the affected page, enabling session theft, redirection, or administrative account takeover. This issue is tracked under CWE-79: Improper Neutralization of Input During Web Page Generation.

Critical Impact

Authenticated contributors can persist malicious JavaScript that executes against every visitor, including administrators, enabling account takeover of the WordPress site.

Affected Products

  • Undsgn Uncode Core plugin for WordPress
  • All versions up to and including 2.9.4.2
  • WordPress sites where contributor-level accounts or above are permitted to author content

Discovery Timeline

  • 2025-07-04 - CVE-2025-6944 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6944

Vulnerability Analysis

The vulnerability resides in the shortcode handlers for uncode_hl_text and uncode_text_icon inside the Uncode Core plugin. Both shortcodes accept user-supplied attributes that are rendered back into page HTML. The plugin does not validate or sanitize these attributes on input, nor does it escape them on output.

Because shortcodes execute during post rendering, any script payload embedded in an attribute is stored in the database and reflected to every subsequent viewer. WordPress permits contributor-level users to author draft content that may include shortcodes, providing the required foot-hold for exploitation.

The scope change reflected in the vulnerability metrics indicates the injected script executes in the browser context of any user viewing the page, including administrators. This can lead to session hijacking, forced administrative actions via CSRF, or privilege escalation through account manipulation.

Root Cause

The root cause is insufficient input sanitization combined with missing output escaping on shortcode attributes. The plugin should apply sanitize_text_field() or wp_kses() on inbound values and esc_attr() or esc_html() when writing them into the DOM. Neither control is present in vulnerable releases.

Attack Vector

Exploitation requires an authenticated account with the WordPress contributor role or higher. The attacker submits a post or page containing a crafted shortcode whose attributes include a JavaScript payload. When an editor previews, an administrator approves, or a visitor loads the published page, the browser parses the unescaped attribute value and executes the injected script.

See the Wordfence Vulnerability Report for additional technical detail.

Detection Methods for CVE-2025-6944

Indicators of Compromise

  • Post or postmeta rows in the wp_posts table containing uncode_hl_text or uncode_text_icon shortcodes with attributes that include <script, javascript:, onerror=, onload=, or onmouseover= substrings.
  • Unexpected outbound requests from visitor browsers to attacker-controlled domains originating from pages using the affected shortcodes.
  • New administrator accounts or role changes shortly after contributors publish or edit content.

Detection Strategies

  • Query the WordPress database for shortcode usage patterns matching uncode_hl_text or uncode_text_icon and inspect their attribute values for HTML event handlers or script tags.
  • Deploy a Web Application Firewall (WAF) rule to flag POST requests to /wp-admin/post.php or the REST API that contain both the target shortcodes and script markers.
  • Review contributor and author activity in the WordPress audit log for anomalous shortcode content in recent posts and revisions.

Monitoring Recommendations

  • Alert on any privilege change events in wp_usermeta following content submission by non-administrative users.
  • Monitor Content Security Policy (CSP) violation reports for inline script executions on pages rendered by the Uncode theme.
  • Track plugin version inventory across managed WordPress sites and alert when Uncode Core versions 2.9.4.2 or earlier are detected.

How to Mitigate CVE-2025-6944

Immediate Actions Required

  • Update the Uncode Core plugin to a version later than 2.9.4.2 on all WordPress installations. Consult the Undsgn Change Log for the fixed release.
  • Audit all existing posts, pages, and revisions for malicious payloads embedded in uncode_hl_text and uncode_text_icon shortcodes and remove any injected script content.
  • Rotate credentials and session cookies for administrative users if compromise is suspected.

Patch Information

Undsgn addressed the issue in a release subsequent to 2.9.4.2. Site owners should upgrade through the WordPress plugin updater or by installing the latest package from the vendor. Confirm the installed version under Plugins after the update completes.

Workarounds

  • Temporarily restrict the contributor, author, and editor roles from publishing content that contains shortcodes until patching is complete.
  • Deploy a WAF rule that blocks HTTP requests carrying uncode_hl_text or uncode_text_icon shortcodes with <script, on*=, or javascript: attribute payloads.
  • Enforce a strict Content Security Policy that disallows inline JavaScript execution on front-end pages to reduce the impact of injected payloads.
bash
# Configuration example: locate vulnerable shortcode usage in a WordPress database
mysql -u wp_user -p wordpress -e "\
  SELECT ID, post_title, post_status FROM wp_posts \
  WHERE (post_content LIKE '%[uncode_hl_text%' \
     OR post_content LIKE '%[uncode_text_icon%') \
     AND (post_content LIKE '%<script%' \
          OR post_content LIKE '%onerror=%' \
          OR post_content LIKE '%javascript:%');"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.