Buttons Shortcode and Widget <= 1.16 - Stored XSS via shortcode
CVE-2024-0711
Summary
The Buttons Shortcode and Widget WordPress plugin, up to version 1.16, has a vulnerability due to improper validation and escaping of shortcode attributes. This oversight could allow users with contributor roles and above to inject malicious scripts into pages or posts where the shortcode is used, leading to potential Stored Cross-Site Scripting (XSS) attacks. Attackers could leverage this flaw to execute scripts in the context of the site, which could compromise user data and site functionality. Website administrators must act swiftly to secure their installations against this vulnerability by ensuring proper sanitization measures are in place.
Affected Version(s)
Buttons Shortcode and Widget 0 <= 1.16
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved