nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-18580 CVE-2017-18580
CRITICALNuclei
getshortcodes shortcodes_ultimate Improper Input Validation
Record summary
CVE-2017-18580 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 31, 2017 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
shortcodes_ultimateBrowse getshortcodes / shortcodes_ultimate | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code ExecutionCVSS 8.8
Shortcodes Ultimate plugin before 5.0.1 for WordPress contains a remote code execution caused by a filter in meta, post, or user shortcode, letting remote attackers execute arbitrary code, exploit requires sending crafted shortcode data.
Impact
Remote attackers can execute arbitrary code on the server, potentially leading to full site compromise.
Remediation
Update to version 5.0.1 or later.
WeaknessesCWE-94
Authors0x_Akoko
Template tagscvecve2017wordpresswp-pluginshortcodes-ultimaterceauthenticatedoastwpvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
https://wpscan.com/vulnerability/efad59c8-e6ae-4167-9c78-d3ea52fe5bba/ https://plugins.trac.wordpress.org/changeset/1756323/shortcodes-ultimate https://blog.sucuri.net/2017/11/formidable-forms-shortcodes-ultimate-exploits-in-the-wild.html https://nvd.nist.gov/vuln/detail/CVE-2017-18580
Source: ProjectDiscovery
References
2wordpress.org
https://wordpress.org/plugins/shortcodes-ultimate