PT-2024-17403 · WordPress · Snippet Shortcodes
Theviper17Y
+1
·
Published
2024-12-12
·
Updated
2024-12-12
·
CVE-2024-12018
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Snippet Shortcodes plugin for WordPress versions up to and including 4.1.6
Description
The issue is related to missing authorization, allowing authenticated attackers with Subscriber-level access and above to delete the plugin's shortcodes. A nonce is used as authentication, but its value is leaked, enabling the unauthorized deletion.
Recommendations
For versions up to and including 4.1.6, update to a version higher than 4.1.6 to resolve the issue. As a temporary workaround, consider restricting access to the shortcodes deletion functionality to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snippet Shortcodes