Record summary

CVE-2017-18580 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 31, 2017 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code ExecutionCVSS 8.8

Shortcodes Ultimate plugin before 5.0.1 for WordPress contains a remote code execution caused by a filter in meta, post, or user shortcode, letting remote attackers execute arbitrary code, exploit requires sending crafted shortcode data.

Impact

Remote attackers can execute arbitrary code on the server, potentially leading to full site compromise.

Remediation

Update to version 5.0.1 or later.

WeaknessesCWE-94
Authors0x_Akoko
Template tagscvecve2017wordpresswp-pluginshortcodes-ultimaterceauthenticatedoastwpvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

2