PT-2024-15093 · WordPress · Custom Fields Shortcode Plugin

Francesco Carlucci

·

Published

2024-03-13

·

Updated

2025-01-21

·

CVE-2023-6809

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Custom fields shortcode plugin for WordPress version 0.1 and earlier
Description The issue arises from insufficient input sanitization and output escaping on user-supplied custom post meta values, allowing authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages. This can lead to the execution of injected scripts whenever a user accesses an injected page.
Recommendations For versions up to and including 0.1, consider disabling the cf shortcode until a patch is available to prevent exploitation. Restrict access to custom post meta values to minimize the risk of arbitrary web script injection. Avoid using the cf shortcode in pages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-6809

Affected Products

Custom Fields Shortcode Plugin