← back to popular plugins
wordfence / plugin · woocommerce-germanized

Germanized for WooCommerce

woocommerce-germanized
total installs
70,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
patched
1
unpatched
0
avg time to patch
vulnerabilities (1)
Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution
medium ✓ patched
cvss score 6.5
cwe CWE-94: Improper Control of Generation of Code ('Code Injection')
published Apr 13, 2026
The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.