plugin

Custom Content Shortcode Vulnerabilities

5 known security issues reported for the Custom Content Shortcode WordPress plugin. Most recent disclosed Feb 22, 2023.

1 high 4 medium

Running Custom Content Shortcode on your site? Check whether your installed version is affected.

Scan your site free

Custom Content Shortcode <= 4.0.2 - Authenticated (Contributor+) Local File Inclusion via Shortcode

high

The Custom Content Shortcode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.2 via a Shortcode attribute. This allows contributor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...

CVSS:
8.8
Affected:
up to 4.0.2
Fix:
No patched version reported
Disclosed:
Feb 22, 2023

CVE-2023-0340 on NVD →

Custom Content Shortcode <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Custom Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...

CVSS:
6.4
Affected:
up to 4.0.2
Fix:
No patched version reported
Disclosed:
Feb 22, 2023

CVE-2023-0273 on NVD →

Custom Content Shortcode <= 4.0.1 - Authenticated Stored Cross-Site Scripting

medium

The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by a...

CVSS:
5.4
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Feb 2, 2022

CVE-2021-24826 on NVD →

Custom Content Shortcode <= 3.8.8 - Unauthorised Arbitrary Post Metadata Access

medium

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of order...

CVSS:
4.3
Affected:
up to 3.8.8
Fixed in:
4.0.1
Disclosed:
Feb 2, 2022

CVE-2021-24824 on NVD →

Custom Content Shortcode <= 4.0.1 - Authenticated Arbitrary File Access / Local File Inclusion

medium

The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP...

CVSS:
4.3
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Feb 2, 2022

CVE-2021-24825 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database