CVE-2025-2803
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Mar 29, 2025
Updated: Apr 1, 2025
CWE ID 94
Summary
CVE-2025-2803 is a vulnerability affecting the So-Called Air Quotes plugin for WordPress. The issue allows unauthenticated attackers to execute arbitrary shortcodes due to the plugin's failure to validate user input before running do_shortcode. This vulnerability can lead to code execution and potential site takeover, putting all WordPress websites utilizing this plugin at risk, regardless of version, up to and including 0.1. Immediate update or removal of the plugin is strongly advised to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.