PT-2025-10423 · WordPress · Code Snippets Cpt

Francesco Carlucci

·

Published

2025-03-08

·

Updated

2025-03-08

·

CVE-2024-13895

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Code Snippets CPT plugin for WordPress versions prior to 2.1.1
Description The issue arises from the software's failure to properly validate a value before executing the do shortcode function, allowing authenticated attackers with Subscriber-level access and above to execute arbitrary shortcodes.
Recommendations For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13895

Affected Products

Code Snippets Cpt