PT-2024-15170 · WordPress · The Pods – Custom Content Types/Fields

Nex Team

·

Published

2024-04-09

·

Updated

2025-01-22

·

CVE-2023-6999

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Pods – Custom Content Types and Fields plugin for WordPress versions prior to 3.0.11, excluding versions 2.7.31.2, 2.8.23.2, and 2.9.19.2
Description The issue allows authenticated attackers with contributor level access or higher to execute code on the server via shortcode. This is a Remote Code Execution vulnerability.
Recommendations For versions prior to 2.7.31.2, update to version 2.7.31.2 or higher. For versions prior to 2.8.23.2, update to version 2.8.23.2 or higher. For versions prior to 2.9.19.2, update to version 2.9.19.2 or higher. For versions 2.7.31.2, 2.8.23.2, and 2.9.19.2, and all versions up to 3.0.10, update to a version higher than 3.0.10. As a temporary workaround, consider restricting access to the shortcode feature until a patch is available.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-6999

Affected Products

The Pods – Custom Content Types/Fields