The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wp Puzzle
Wp Puzzle hide Links |
|
CPEs | cpe:2.3:a:wp_puzzle:hide_links:*:*:*:*:*:*:*:* | |
Vendors & Products |
Wp Puzzle
Wp Puzzle hide Links |
|
Metrics |
ssvc
|
Wed, 13 Nov 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site. | |
Title | Hide Links <= 1.4.2 - Unauthenticated Shortcode Execution | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-13T02:02:29.677Z
Updated: 2024-11-13T15:51:09.459Z
Reserved: 2024-10-07T12:35:19.941Z
Link: CVE-2024-9578
Vulnrichment
Updated: 2024-11-13T15:51:04.402Z
NVD
Status : Awaiting Analysis
Published: 2024-11-13T02:15:20.340
Modified: 2024-11-13T17:01:16.850
Link: CVE-2024-9578
Redhat
No data.