Medium 6.4
2025-07-04< 2.9.4.3
Uncode Core <= 2.9.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
Minimum safe version
2.9.4.3
Update to 2.9.4.3 or later to address 5 fixable vulnerabilities
Uncode Core <= 2.9.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
CVE-2024-13689
WordPress Uncode Core Plugin <= 2.8.8 is vulnerable to Arbitrary File Deletion
WordPress Uncode Core Plugin <= 2.8.8 is vulnerable to Privilege Escalation
WordPress Uncode Core Plugin <= 2.8.6 is vulnerable to Cross Site Scripting (XSS)