4.3

CVE-2021-24824

Exploit

Custom Content Shortcode < 4.0.1 - Unauthorised Arbitrary Post Metadata Access

Custom Content Shortcode <= 3.8.8 - Unauthorised Arbitrary Post Metadata Access

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved
Mögliche Gegenmaßnahme
Custom Content Shortcode: Update to version 4.0.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Custom Content Shortcode ProjectCustom Content Shortcode SwPlatformwordpress Version < 4.0.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Custom Content Shortcode
Version *-3.8.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.511
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://wpscan.com/vulnerability/7b4d4675-6089-4435-9b56-31496adc4767
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/6d2e3252-454c-47a2-a09d-5d0474c82e2b
Third Party Advisory