Filtered by vendor Webliberty Subscriptions
Filtered by product Simple Spoiler Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-8479 1 Webliberty 1 Simple Spoiler 2024-09-16 7.3 High
The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.