CVE-2024-8481
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Sep 25, 2024
Updated: Dec 26, 2024
CWE ID 94
Summary
CVE-2024-8481: The Special Text Boxes plugin for WordPress, used in versions up to and including 6.2.2, is susceptible to arbitrary shortcode execution in comments. Due to the addition of the filter 'add_filter('comment_text', 'do_shortcode')' by the plugin, attackers can execute unauthenticated arbitrary shortcodes, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.