CVE-2024-10958: WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay
The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10958?
CVE-2024-10958 is considered a high severity vulnerability due to its potential for arbitrary shortcode execution.
How do I fix CVE-2024-10958?
To fix CVE-2024-10958, upgrade the WP Photo Album Plus plugin to version 8.9.01.001 or later.
Which versions of WP Photo Album Plus are affected by CVE-2024-10958?
CVE-2024-10958 affects all versions of the WP Photo Album Plus plugin up to and including 8.8.08.007.
What type of vulnerability is CVE-2024-10958?
CVE-2024-10958 is an arbitrary shortcode execution vulnerability that can be exploited through the getshortcodedrenderedfenodelay AJAX action.
Who is affected by CVE-2024-10958?
Any WordPress users utilizing the WP Photo Album Plus plugin versions up to 8.8.08.007 are potentially affected by CVE-2024-10958.