CVE-2022-34487
WordPress Shortcode Addons plugin <= 3.0.2 - Unauthenticated Arbitrary Option Update vulnerability
Record summary
CVE-2022-34487 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 30, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Shortcode Addons (WordPress plugin)Browse biplob018 / Shortcode Addons (WordPress plugin) | CVE List | <= 3.0.2 to ≤ 3.0.2 | affected |
Shortcode Addons PluginBrowse oxilab / Shortcode Addons Plugin | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALShortCode Addons - Unauthenticated Options UpdateCVSS 9.8
WordPress plugin Shortcode Addons <= 3.0.2 contains an unauthenticated arbitrary option update caused by insufficient access controls in the plugin, letting attackers modify options without authentication.
Impact
Attackers can modify plugin options arbitrarily, potentially leading to site defacement, data tampering, or further exploitation.
Remediation
Update to the latest version of Shortcode Addons plugin.
Source: ProjectDiscovery