CVE-2024-10958
10.11.2024, 13:15
The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Vendor | Product | Version |
---|---|---|
opajaap | wp_photo_album_plus | 𝑥 ≤ 8.8.08.007 |
wppa | wp_photo_album_plus | 𝑥 < 8.9.01.001 |
𝑥
= Vulnerable software versions
References