CVE-2024-8479

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
14/09/2024
Last modified:
27/09/2024

Description

The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:webliberty:simple_spoiler:*:*:*:*:*:wordpress:*:* 1.2 (including) 1.4 (excluding)