CVE-2017-18580: Input Validation
Published Aug 22, 2019
·Updated
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
Affected Software
1 affected component
Getshortcodes Shortcodes Ultimate Wordpress<5.0.1
Event History
Aug 22, 2019
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18580?
CVE-2017-18580 is a vulnerability in the shortcodes-ultimate plugin before version 5.0.1 for WordPress.
2
How does CVE-2017-18580 allow remote code execution?
CVE-2017-18580 allows remote code execution through a filter in a meta, post, or user shortcode.
3
What is the severity rating of CVE-2017-18580?
CVE-2017-18580 has a severity rating of critical with a score of 9.8.
4
How can I fix CVE-2017-18580?
To fix CVE-2017-18580, update the shortcodes-ultimate plugin to version 5.0.1 or higher.