Vulnerability Description
The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export arbitrary options.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jozoor | Shortcode Cleaner Lite | <= 1.0.9 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/shortcode-cleaner-lite/trunk/vendor/cProduct
- https://wordpress.org/plugins/shortcode-cleaner-lite/#developersProduct
- https://www.wordfence.com/threat-intel/vulnerabilities/id/15613da5-f900-4a33-8eeThird Party Advisory
FAQ
What is CVE-2025-1481?
CVE-2025-1481 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in all versions up to, and including, 1...
How severe is CVE-2025-1481?
CVE-2025-1481 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1481?
Check the references section above for vendor advisories and patch information. Affected products include: Jozoor Shortcode Cleaner Lite.