PT-2024-16662 · WordPress · Wp Photo Album Plus

Arkadiusz Hydzik

·

Published

2024-11-10

·

Updated

2024-11-16

·

CVE-2024-10958

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Photo Album Plus versions prior to 8.8.08.007 WP Photo Album Plus versions prior to 8.8.08.004
Description The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via the getshortcodedrenderedfenodelay AJAX action. This issue is due to the software allowing users to execute an action that does not properly validate a value before running do shortcode, making it possible for unauthenticated attackers to execute arbitrary shortcodes.
Recommendations For WP Photo Album Plus versions prior to 8.8.08.007, update to the latest version to mitigate risks. For WP Photo Album Plus versions prior to 8.8.08.004, update to the latest version to mitigate risks. As a temporary workaround, consider disabling the getshortcodedrenderedfenodelay AJAX action until a patch is available.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-10958

Affected Products

Wp Photo Album Plus