PT-2024-39878 · WordPress · Uix Slideshow

Francesco Carlucci

·

Published

2024-11-15

·

Updated

2024-11-21

·

CVE-2024-9839

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Uix Slideshow plugin for WordPress versions up to, and including, 1.6.5
Description The issue is due to the software allowing users to execute an action that does not properly validate a value before running do shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability allows unauthenticated attackers to execute arbitrary shortcodes.
Recommendations For versions up to, and including, 1.6.5, update to a version later than 1.6.5 to resolve the issue. As a temporary workaround, consider disabling the execution of shortcodes until a patch is available. Restrict access to the plugin to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-9839

Affected Products

Uix Slideshow