Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vendidero
Vendidero germanized For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Vendidero
Vendidero germanized For Woocommerce Wordpress Wordpress wordpress |
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | |
| Title | Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-14T14:04:52.319Z
Reserved: 2026-02-16T12:12:39.009Z
Link: CVE-2026-2582
Updated: 2026-04-14T14:04:03.651Z
Status : Deferred
Published: 2026-04-14T07:16:06.993
Modified: 2026-04-22T20:23:16.350
Link: CVE-2026-2582
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:30:48Z