CVE-2024-13453: Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.6.0 - Unauthenticated Arbitrary Shortcode Execution
The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.6.0. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13453?
CVE-2024-13453 has a severity rating of high due to the potential for arbitrary shortcode execution.
How do I fix CVE-2024-13453?
To fix CVE-2024-13453, you should update the Contact Form & SMTP Plugin for WordPress to version 2.6.1 or later.
What versions are affected by CVE-2024-13453?
CVE-2024-13453 affects all versions of the Contact Form & SMTP Plugin for WordPress up to and including 2.6.0.
What kind of vulnerability is CVE-2024-13453?
CVE-2024-13453 is a vulnerability that allows for arbitrary shortcode execution due to improper validation.
Who is the vendor for the Contact Form & SMTP Plugin vulnerable to CVE-2024-13453?
The vendor for the vulnerable Contact Form & SMTP Plugin is PirateForms.