Vulnerability Description
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nicdark | Nd Shortcodes | < 7.0 |
References
- https://wpscan.com/vulnerability/0805ed7e-395d-48de-b484-6c3ec1cd4b8eExploitThird Party Advisory
- https://wpscan.com/vulnerability/0805ed7e-395d-48de-b484-6c3ec1cd4b8eExploitThird Party Advisory
FAQ
What is CVE-2023-1273?
CVE-2023-1273 is a vulnerability with a CVSS score of 8.8 (HIGH). The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as sub...
How severe is CVE-2023-1273?
CVE-2023-1273 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-1273?
Check the references section above for vendor advisories and patch information. Affected products include: Nicdark Nd Shortcodes.