Custom Content Shortcode Project ≫ Custom Content Shortcode
5 Schwachstellen gefunden.
CVE-2023-0340
- EPSS 0.54%
- Veröffentlicht 20.03.2023 16:15:12
- Zuletzt bearbeitet 26.02.2025 19:15:15
The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to r...
CVE-2023-0273
- EPSS 0.14%
- Veröffentlicht 20.03.2023 16:15:11
- Zuletzt bearbeitet 26.02.2025 19:15:15
The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and a...
CVE-2021-24824
- EPSS 0.23%
- Veröffentlicht 07.03.2022 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:50
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example...
CVE-2021-24825
- EPSS 0.09%
- Veröffentlicht 07.03.2022 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:50
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, ....
CVE-2021-24826
- EPSS 0.18%
- Veröffentlicht 07.03.2022 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:50
The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_h...