CVE-2023-6226
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Nov 28, 2023
Updated: Dec 4, 2023
CWE ID 639
Summary
CVE-2023-6226: The WP Shortcodes Plugin, specifically the Shortcodes Ultimate plugin for WordPress, contains a vulnerability that allows authenticated attackers with contributor-level access or higher to retrieve arbitrary post meta values. This issue occurs due to missing validation for user-controlled keys 'key' and 'post_id' in the su_meta shortcode. The impact of this vulnerability can result in the disclosure of sensitive information when combined with another plugin. All versions up to and including 5.13.3 are affected.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share