CVE-2024-12417: Simple Link Directory <= 8.4.5 - Unauthenticated Arbitrary Shortcode Execution
The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12417?
CVE-2024-12417 is regarded as a medium severity vulnerability due to its potential to allow arbitrary shortcode execution.
How do I fix CVE-2024-12417?
To address CVE-2024-12417, you should update the Simple Link Directory plugin to the latest version beyond 8.4.0.
Who is affected by CVE-2024-12417?
Any user running Simple Link Directory plugin version 8.4.0 or earlier on their WordPress site is affected by CVE-2024-12417.
What kind of attacks can CVE-2024-12417 facilitate?
CVE-2024-12417 can facilitate attacks where an attacker could execute arbitrary PHP code through shortcode injection.
Is CVE-2024-12417 publicly known?
Yes, CVE-2024-12417 is publicly disclosed and users should be aware of the risks associated with the vulnerability.