The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 25 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-25T16:20:36.240Z
Reserved: 2023-03-08T15:34:20.038Z
Link: CVE-2023-1273
Updated: 2024-08-02T05:40:59.688Z
Status : Modified
Published: 2023-07-04T08:15:10.123
Modified: 2024-11-21T07:38:48.267
Link: CVE-2023-1273
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.