WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
CVE-2024-31114
9.1CRITICAL
Summary
The vulnerability in Biplob018's Shortcode Addons arises from an unrestricted file upload mechanism. This flaw allows attackers to upload potentially malicious files, leading to unauthorized execution of code on affected systems. The affected versions, including 3.2.5, are susceptible to exploitation if proper validation and sanitization measures are not enforced, posing a significant risk to users. It is crucial for users of Shortcode Addons to take immediate action to mitigate the impacts of this vulnerability.
Affected Version(s)
Shortcode Addons <= 3.2.5
References
EPSS Score
60% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Credit
Peng Zhou (Patchstack Alliance)