WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
CVE-2024-31114

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 March 2024

What is CVE-2024-31114?

The vulnerability in Biplob018's Shortcode Addons arises from an unrestricted file upload mechanism. This flaw allows attackers to upload potentially malicious files, leading to unauthorized execution of code on affected systems. The affected versions, including 3.2.5, are susceptible to exploitation if proper validation and sanitization measures are not enforced, posing a significant risk to users. It is crucial for users of Shortcode Addons to take immediate action to mitigate the impacts of this vulnerability.

Affected Version(s)

Shortcode Addons <= 3.2.5

References

EPSS Score

42% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Peng Zhou (Patchstack Alliance)
.