PT-2024-17588 · WordPress · Wpmobile.App

Arkadiusz Hydzik

·

Published

2024-12-13

·

Updated

2024-12-13

·

CVE-2024-12420

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPMobile.App — Android and iOS Mobile Application plugin for WordPress versions up to, and including, 11.52
Description The issue allows unauthenticated attackers to execute arbitrary shortcodes due to the software permitting users to execute an action without properly validating a value before running do shortcode. This makes it possible for attackers to execute arbitrary shortcodes.
Recommendations For versions up to, and including, 11.52, update to a version later than 11.52 to resolve the issue. As a temporary workaround, consider restricting access to the do shortcode function until a patch is available.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-12420

Affected Products

Wpmobile.App