Absolute Path Traversal Vulnerability Affects Shortcodes Ultimate
CVE-2023-25050

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
17 May 2024

Summary

A vulnerability exists in the Shortcodes Ultimate plugin developed by Vova Anokhin, allowing for a Path Traversal attack. This flaw enables attackers to manipulate file paths, which could lead to unauthorized access to sensitive files on the server. The vulnerability affects all versions up to and including 5.12.6, making it essential for users to act swiftly to mitigate risks. Ensuring proper access controls is crucial to safeguard against potential exploits.

Affected Version(s)

Shortcodes Ultimate <= 5.12.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.