The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note that a nonce is used as authentication here, but the value is leaked. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's Shortcodes.
History

Thu, 12 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Dec 2024 05:30:00 +0000

Type Values Removed Values Added
Description The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note that a nonce is used as authentication here, but the value is leaked. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's Shortcodes.
Title Snippet Shortcodes <= 4.1.6 - Authenticated (Subscriber+) Shortcode Deletion
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-12-12T05:24:20.501Z

Updated: 2024-12-12T14:53:56.371Z

Reserved: 2024-12-02T14:22:13.775Z

Link: CVE-2024-12018

cve-icon Vulnrichment

Updated: 2024-12-12T14:53:52.452Z

cve-icon NVD

Status : Received

Published: 2024-12-12T06:15:22.737

Modified: 2024-12-12T06:15:22.737

Link: CVE-2024-12018

cve-icon Redhat

No data.