Arbitrary Shortcode Execution in Code Snippets CPT Plugin for WordPress
CVE-2024-13895
6.3MEDIUM
What is CVE-2024-13895?
The Code Snippets CPT plugin for WordPress is susceptible to a security flaw that permits authenticated users, including those with Subscriber-level access, to execute arbitrary shortcodes. This issue arises from inadequate validation of inputs prior to processing the 'do_shortcode' function. It affects all versions up to and including 2.1.0, posing significant risks to site functionality and security if exploited.
Affected Version(s)
Code Snippets CPT * <= 2.1.0