Vulnerabilities (CVE)

Filtered by vendor Nicdark Subscribe
Filtered by product Nd Shortcodes
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-1273 1 Nicdark 1 Nd Shortcodes 2023-12-10 N/A 8.8 HIGH
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
CVE-2022-4623 1 Nicdark 1 Nd Shortcodes 2023-12-10 N/A 5.4 MEDIUM
The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks