Custom Content Shortcode Project
Custom Content Shortcode Project Custom Content Shortcode: vulnerabilidades y CVE
Custom Content Shortcode Project Custom Content Shortcode tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-0340 | Alta (8.8) | 1.0% | — | 20 mar 2023 | The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack.… |
| CVE-2023-0273 | Media (5.4) | 0.44% | — | 20 mar 2023 | The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users… |
| CVE-2021-24826 | Media (5.4) | 0.60% | — | 7 mar 2022 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting… |
| CVE-2021-24825 | Media (4.3) | 0.44% | — | 7 mar 2022 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from… |
| CVE-2021-24824 | Media (4.3) | 0.79% | — | 7 mar 2022 | The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to… |