Filtered by vendor Nicdark Subscriptions
Filtered by product Nd Shortcodes Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-1273 1 Nicdark 1 Nd Shortcodes 2024-11-25 8.8 High
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
CVE-2022-4623 1 Nicdark 1 Nd Shortcodes 2024-11-22 5.4 Medium
The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks