CVE-2024-8479 - "WordPress Simple Spoiler Plugin Arbitrary Shortcode Execution Vulnerability"

1 month ago 21
ARTICLE AD BOX
CVE ID : CVE-2024-8479
Published : Sept. 14, 2024, 4:15 a.m. | 24 minutes ago
Description : The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article