CVE-2023-1273

The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
Configurations

Configuration 1 (hide)

cpe:2.3:a:nicdark:nd_shortcodes:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:38

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/0805ed7e-395d-48de-b484-6c3ec1cd4b8e - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/0805ed7e-395d-48de-b484-6c3ec1cd4b8e - Exploit, Third Party Advisory

Information

Published : 2023-07-04 08:15

Updated : 2024-11-21 07:38


NVD link : CVE-2023-1273

Mitre link : CVE-2023-1273

CVE.ORG link : CVE-2023-1273


JSON object : View

Products Affected

nicdark

  • nd_shortcodes
CWE

No CWE.