PT-2024-16143 · WordPress · Drop Shadow Boxes

Arkadiusz Hydzik

·

Published

2024-11-15

·

Updated

2024-11-18

·

CVE-2024-10262

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Drop Shadow Boxes plugin for WordPress versions up to, and including, 1.7.14
Description The issue is related to arbitrary shortcode execution due to the software allowing users to execute an action that does not properly validate a value before running do shortcode(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Recommendations For versions up to, and including, 1.7.14, update to a version later than 1.7.14 to resolve the issue. As a temporary workaround, consider restricting access to the do shortcode() function or limiting the execution of shortcodes to trusted users until a patch is available.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-10262

Affected Products

Drop Shadow Boxes