CVE-2026-2582 PUBLISHED

Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution

Assigner: Wordfence
Reserved: 16.02.2026 Published: 14.04.2026 Updated: 14.04.2026

The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 6.5

Product Status

Vendor vendidero
Product Germanized for WooCommerce
Versions Default: unaffected
  • affected from 0 to 3.20.5 (incl.)

Credits

  • Chiao-Lin Yu finder

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE