First published: Tue Nov 28 2023(Updated: )
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve arbitrary post meta values which may contain sensitive information when combined with another plugin.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shortcodes Ultimate by Vova Anokhin | <7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6226 is a vulnerability in the WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress that allows for Insecure Direct Object Reference.
CVE-2023-6226 has a severity score of 4.3, which is considered medium.
All versions up to, and including, 5.13.3 of the Shortcodes Ultimate plugin for WordPress are affected by CVE-2023-6226.
CVE-2023-6226 allows for Insecure Direct Object Reference, which can lead to unauthorized access to sensitive data or resources.
To mitigate CVE-2023-6226, it is recommended to update your Shortcodes Ultimate plugin for WordPress to version 7.0.0 or higher.