CVE-2023-1273: ND Shortcodes < 7.0 - Subscriber+ LFI
Published Jul 4, 2023
·Updated
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
Affected Software
1 affected component
Nicdark Nd Shortcodes Wordpress<7.0
Event History
Jul 4, 2023
CVE Published
via MITRE·07:23 AM
Data Sourced
via MITRE·07:23 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1273?
CVE-2023-1273 has a medium severity rating due to its potential for local file inclusion (LFI) attacks.
2
Who is affected by CVE-2023-1273?
CVE-2023-1273 affects users of the ND Shortcodes WordPress plugin before version 7.0.
3
How do I fix CVE-2023-1273?
To mitigate CVE-2023-1273, update the ND Shortcodes WordPress plugin to version 7.0 or later.
4
What type of attack can CVE-2023-1273 allow?
CVE-2023-1273 allows authenticated users to perform local file inclusion (LFI) attacks on vulnerable sites.
5
What versions of the ND Shortcodes WordPress plugin are vulnerable to CVE-2023-1273?
Versions of the ND Shortcodes WordPress plugin prior to 7.0 are vulnerable to CVE-2023-1273.