Executive brief
The Forget About Shortcode Buttons plugin for WordPress, which helps users easily add visual buttons to their website content, contains a security flaw that allows users with low-level 'Contributor' permissions to perform actions they should not be authorized to do. This could allow an internal user to modify certain site settings or content beyond their intended role. While the risk is considered medium, it could lead to unauthorized changes to the website's appearance or functionality.
Technical details
A broken access control vulnerability exists in the Forget About Shortcode Buttons plugin for WordPress (versions up to and including 2.1.3) due to missing authorization checks (CWE-862). An attacker with Contributor-level privileges can exploit this flaw via network requests to execute functions that should be restricted to higher-privileged users. The vulnerability allows for unauthorized integrity and availability impacts, though it does not currently facilitate data disclosure. As of the advisory date, no official patch has been released, and users are advised to monitor for updates from the developer.
Affected products
- Code Amp Forget About Shortcode Buttons <= 2.1.3
Timeline
- 2025-10-22: other: Reported by Nabil Irawan
- 2026-06-26: advisory: Published by Patchstack
- 2026-06-26: disclosed: NVD published date