Custom Content Shortcode Project

Custom Content Shortcode

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.54%
  • Veröffentlicht 20.03.2023 16:15:12
  • Zuletzt bearbeitet 26.02.2025 19:15:15

The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to r...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 20.03.2023 16:15:11
  • Zuletzt bearbeitet 26.02.2025 19:15:15

The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and a...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 07.03.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 05:53:50

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 07.03.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 05:53:50

The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, ....

Exploit
  • EPSS 0.18%
  • Veröffentlicht 07.03.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 05:53:50

The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_h...