The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 16 Nov 2024 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes. | |
Title | Drop Shadow Boxes <= 1.7.14 - Authenticated (Subscriber+) Arbitrary Shortcode Execution | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-16T03:20:53.725Z
Updated: 2024-11-19T16:06:53.739Z
Reserved: 2024-10-22T20:40:28.785Z
Link: CVE-2024-10262

Updated: 2024-11-18T21:52:40.993Z

Status : Awaiting Analysis
Published: 2024-11-16T04:15:04.587
Modified: 2024-11-18T17:11:17.393
Link: CVE-2024-10262

No data.