CVE-2024-7381

The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.
Configurations

Configuration 1 (hide)

cpe:2.3:a:infinitumform:geo_controller:*:*:*:*:*:wordpress:*:*

History

06 Sep 2024, 10:44

Type Values Removed Values Added
Summary
  • (es) El complemento Geo Controller para WordPress es vulnerable a la ejecución no autorizada de códigos cortos debido a la falta de comprobaciones de autorización y capacidad en la función ajax__shortcode_cache en todas las versiones hasta la 8.6.9 incluida. Esto permite que atacantes no autenticados ejecuten códigos cortos arbitrarios disponibles en el sitio de destino.
First Time Infinitumform
Infinitumform geo Controller
CPE cpe:2.3:a:infinitumform:geo_controller:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/cf-geoplugin/tags/8.6.9/inc/classes/Shortcodes.php#L1932 - () https://plugins.trac.wordpress.org/browser/cf-geoplugin/tags/8.6.9/inc/classes/Shortcodes.php#L1932 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/4ed7b13a-eec3-4035-8815-15228fb05af1?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/4ed7b13a-eec3-4035-8815-15228fb05af1?source=cve - Third Party Advisory

05 Sep 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-05 11:15

Updated : 2024-09-06 10:44


NVD link : CVE-2024-7381

Mitre link : CVE-2024-7381

CVE.ORG link : CVE-2024-7381


JSON object : View

Products Affected

infinitumform

  • geo_controller
CWE
CWE-862

Missing Authorization