Unauthenticated Shortcode Execution Vulnerability in Booster for WooCommerce by WordPress
CVE-2024-3957

7.3HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 May 2024

What is CVE-2024-3957?

The Booster for WooCommerce plugin is susceptible to a vulnerability that enables unauthenticated attackers to execute arbitrary shortcodes. This risk is present in versions up to and including 7.1.8. The impact of this vulnerability can vary based on the additional plugins installed and the functionality of the shortcodes they offer, potentially leading to unauthorized actions on affected WordPress sites.

Affected Version(s)

Booster for WooCommerce * <= 7.1.8

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthew Rollings
.