First published: Thu Aug 22 2019(Updated: )
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Shortcodes Ultimate by Vova Anokhin | <5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18580 is a vulnerability in the shortcodes-ultimate plugin before version 5.0.1 for WordPress.
CVE-2017-18580 allows remote code execution through a filter in a meta, post, or user shortcode.
CVE-2017-18580 has a severity rating of critical with a score of 9.8.
To fix CVE-2017-18580, update the shortcodes-ultimate plugin to version 5.0.1 or higher.