Security Advisory

CVE-2023-1273

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-07-04 07:23:31
Last updated 2024-11-25 16:20:36
Assigner WPScan
State PUBLISHED

Description

The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks