CVE-2024-13792: WooCommerce Food - Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids
The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13792?
CVE-2024-13792 is considered to have a high severity due to the potential for arbitrary shortcode execution.
How do I fix CVE-2024-13792?
To fix CVE-2024-13792, update the WooCommerce Food - Restaurant Menu & Food Ordering plugin to version 3.3.3 or later.
Who is affected by CVE-2024-13792?
CVE-2024-13792 affects all versions of the WooCommerce Food - Restaurant Menu & Food Ordering plugin up to and including 3.3.2.
What is the nature of the vulnerability in CVE-2024-13792?
CVE-2024-13792 involves arbitrary shortcode execution due to improper validation of user inputs.
Is CVE-2024-13792 a remote code execution vulnerability?
CVE-2024-13792 allows users to execute custom shortcodes, which may lead to remote code execution if exploited.