HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-2169
发布日期2025-03-11T03:22:19.663Z
更新日期2025-03-11T13:50:33.061Z
状态PUBLISHED
受影响的供应商realmag777
受影响的产品WPCS – WordPress Currency Switcher Professional
描述The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

参考链接:

Image Additional Image