Lucene search

K
wpvulndbWpvulndbWPVDB-ID:87F9629F-DED5-46C1-B374-C42499F94AE7
HistoryNov 29, 2023 - 12:00 a.m.

WP Shortcodes Plugin — Shortcodes Ultimate < 7.0.0 - Insecure Direct Object Reference to Information Disclosure

2023-11-2900:00:00
wpscan.com
9
wordpress
plugin
vulnerability
direct object reference
information disclosure
authentication
post meta values
validation

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

19.0%

Description The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys ‘key’ and ‘post_id’. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve arbitrary post meta values which may contain sensitive information when combined with another plugin.

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

19.0%

Related for WPVDB-ID:87F9629F-DED5-46C1-B374-C42499F94AE7