WordPress Core, up to version 6.3.1, has a security vulnerability that allows attackers with subscriber-level or higher privileges to execute any type of code. This vulnerability is due to a lack of input validation for the ‘shortcode’ parameter in the parse_media_shortcode AJAX function.