CVE-2023-1273

The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:nicdark:nd_shortcodes:*:*:*:*:*:wordpress:*:*

History

07 Nov 2023, 04:02

Type Values Removed Values Added
CWE CWE-22

11 Jul 2023, 16:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References (MISC) https://wpscan.com/vulnerability/0805ed7e-395d-48de-b484-6c3ec1cd4b8e - (MISC) https://wpscan.com/vulnerability/0805ed7e-395d-48de-b484-6c3ec1cd4b8e - Exploit, Third Party Advisory
First Time Nicdark
Nicdark nd Shortcodes
CPE cpe:2.3:a:nicdark:nd_shortcodes:*:*:*:*:*:wordpress:*:*

04 Jul 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-04 08:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-1273

Mitre link : CVE-2023-1273

CVE.ORG link : CVE-2023-1273


JSON object : View

Products Affected

nicdark

  • nd_shortcodes
CWE

No CWE.