Unauthorized Shortcode Deletion Vulnerability in Snippet Shortcodes plugin
CVE-2024-12018
4.3MEDIUM
What is CVE-2024-12018?
The Snippet Shortcodes plugin for WordPress contains a vulnerability that allows unauthorized deletion of shortcodes due to a lack of proper authorization checks. Although nonce values are utilized for authentication, they are being leaked, which enables authenticated attackers with Subscriber-level access and above to delete shortcodes from the plugin. This security flaw can compromise the functionality and integrity of websites utilizing the affected version of the plugin.
Affected Version(s)
Snippet Shortcodes * <= 4.1.6