CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Custom Content Shortcode Project 1Custom Content Shortcode Feb 26, 2025 Mar 20, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. T...Show more |
1Custom Content Shortcode Project 1Custom Content Shortcode Feb 26, 2025 Mar 20, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users w...Show more |
1Custom Content Shortcode Project 1Custom Content Shortcode Nov 21, 2024 Mar 7, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting atta...Show more |
1Custom Content Shortcode Project 1Custom Content Shortcode Nov 21, 2024 Mar 7, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from t...Show more |
1Custom Content Shortcode Project 1Custom Content Shortcode Nov 21, 2024 Mar 7, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitiv...Show more |