VYPR
Medium severity6.5NVD Advisory· Published Mar 15, 2025· Updated Apr 23, 2026

CVE-2025-26924

CVE-2025-26924

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Ohio Extra: from n/a through <= 3.4.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Ohio Extra plugin for WordPress <=3.4.7 allows unauthenticated code injection via shortcode, enabling content injection attacks.

Vulnerability

Overview The Ohio Extra plugin for WordPress (versions up to and including 3.4.7) contains an Improper Control of Generation of Code (Code Injection) vulnerability [1]. This flaw allows an attacker to inject arbitrary shortcodes, enabling code injection within the affected WordPress installations.

Exploitation

Attackers can exploit this vulnerability without authentication by sending specially crafted requests containing malicious shortcodes. The vulnerability is classified as content injection (CAPEC-242), which enables the injection of arbitrary content into posts or pages [1]. No special privileges or complex conditions are required for exploitation.

Impact

Successful exploitation allows an attacker to inject their own content into the target website's pages and posts. This can be abused to insert phishing pages or other malicious content, potentially compromising visitors' data or credentials. The vulnerability is considered moderately dangerous and is expected to be used in automated mass-exploit campaigns against thousands of sites [1].

Mitigation

The vendor has not released a patch; the recommended immediate action is to update the plugin to a version beyond 3.4.7 once available. If updating is not immediately possible, users should consult their hosting provider or web developer for mitigation strategies [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.