WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
CVE-2024-31114

9.1CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
31 March 2024

Summary

The vulnerability in Biplob018's Shortcode Addons arises from an unrestricted file upload mechanism. This flaw allows attackers to upload potentially malicious files, leading to unauthorized execution of code on affected systems. The affected versions, including 3.2.5, are susceptible to exploitation if proper validation and sanitization measures are not enforced, posing a significant risk to users. It is crucial for users of Shortcode Addons to take immediate action to mitigate the impacts of this vulnerability.

Affected Version(s)

Shortcode Addons <= 3.2.5

References

EPSS Score

60% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Peng Zhou (Patchstack Alliance)
.