AJAX Action Vulnerability in nd-shortcodes Plugin for WordPress
CVE-2019-15771
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 29 August 2019
What is CVE-2019-15771?
The nd-shortcodes plugin for WordPress contains a vulnerability that enables unauthorized users to modify critical site settings through an unprotected AJAX action. Specifically, the nopriv_ AJAX action in versions prior to 6.0 allows attackers to change the siteurl setting, potentially leading to broader site compromises. This vulnerability emphasizes the importance of securing AJAX actions within WordPress plugins to prevent unauthorized alterations and maintain site integrity.