Record summary

CVE-2024-9772 has a selected CVSS score of 7.3 (high); EIP currently links 1 Nuclei template.

Description

The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 28, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE ListThrough 1.9.9affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress UIX Shortcodes <= 1.9.7 - Unauthenticated Shortcode ExecutionCVSS 7.3

The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Impact

Unauthenticated attackers can execute arbitrary shortcodes through the uixscform_ajax_shortcodepreview AJAX action, potentially leading to information disclosure, privilege escalation, or remote code execution depending on available shortcodes.

Remediation

Update UIX Shortcodes plugin to the latest patched version (>= 1.9.8).

WeaknessesCWE-94
Authorskankburhan
Template tagscvecve2024wordpresswp-pluginwpwpscanshortcodeuix-shortcodesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CPE: cpe:2.3:a:uiux:uix_shortcodes:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4