CVE-2024-10262
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Nov 16, 2024
CWE ID 94
Summary
CVE-2024-10262 is a vulnerability affecting the Drop Shadow Boxes plugin for WordPress. In versions up to and including 1.7.14, the plugin fails to adequately validate user input before running do_shortcode, enabling authenticated attackers with Subscriber-level access or above to execute arbitrary shortcodes. Successful exploitation may lead to unintended functionality, data leaks, or even complete site takeover. WordPress users are advised to update to the latest version of the plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.