PT-2024-39697 · WordPress · Hide Links

Francesco Carlucci

·

Published

2024-11-13

·

Updated

2025-07-09

·

CVE-2024-9578

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Hide Links plugin for WordPress versions up to and including 1.4.2
Description The issue allows unauthorized shortcode execution due to do shortcode being hooked through the comment text filter. This enables unauthenticated attackers to execute arbitrary shortcodes available on the target site.
Recommendations For versions up to and including 1.4.2, update to a version that fixes the unauthorized shortcode execution issue. As a temporary workaround, consider disabling the do shortcode function hooked through the comment text filter until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-9578

Affected Products

Hide Links