HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2024-13895
发布日期2025-03-08T02:24:04.601Z
更新日期2025-03-10T16:00:26.958Z
状态PUBLISHED
受影响的供应商jtsternberg
受影响的产品Code Snippets CPT
描述The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.

参考链接:

Image Additional Image