What the vulnerability does
01Description
Missing Authorization vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arconix Shortcodes: from n/a through <= 2.1.18.
Explanation of Vulnerability in Simple Terms
02Summary
Arconix Shortcodes through version 2.1.18 fails to properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read data they should not have access to. The vulnerability does not allow data modification or site unavailability. Update to a version newer than 2.1.18.
What an attacker can do
03Attacker Capabilities
Read sensitive data they should not have access to as a low-privilege user.
Potential impact on your site
04Site Impact
Unauthorized users can view restricted information; data integrity and availability are not affected.
Conditions required to exploit
05Prerequisites
Attacker must be logged in to the site with a low-privilege account.
Key dates
06Disclosure timeline
November 21, 2025
CVE published
April 28, 2026
Record updated