Custom Content Shortcode <= 4.0.2 - Authenticated (Contributor+) Local File Inclusion via Shortcode
high
The Custom Content Shortcode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.2 via a Shortcode attribute. This allows contributor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 8.8
- Affected:
- up to 4.0.2
- Fix:
- No patched version reported
- Disclosed:
- Feb 22, 2023
CVE-2023-0340 on NVD →
Custom Content Shortcode <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Custom Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...
- CVSS:
- 6.4
- Affected:
- up to 4.0.2
- Fix:
- No patched version reported
- Disclosed:
- Feb 22, 2023
CVE-2023-0273 on NVD →
Custom Content Shortcode <= 4.0.1 - Authenticated Stored Cross-Site Scripting
medium
The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by a...
- CVSS:
- 5.4
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Feb 2, 2022
CVE-2021-24826 on NVD →
Custom Content Shortcode <= 3.8.8 - Unauthorised Arbitrary Post Metadata Access
medium
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of order...
- CVSS:
- 4.3
- Affected:
- up to 3.8.8
- Fixed in:
- 4.0.1
- Disclosed:
- Feb 2, 2022
CVE-2021-24824 on NVD →
Custom Content Shortcode <= 4.0.1 - Authenticated Arbitrary File Access / Local File Inclusion
medium
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP...
- CVSS:
- 4.3
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Feb 2, 2022
CVE-2021-24825 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database