Back

HIGH

Shortcodes AnyWhere <= 1.0.1 - Unauthenticated Arbitrary Shortcode Execution

Published Oct 10, 2024

Description

The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Wordfence
Published Oct 10, 2024
Updated Apr 8, 2026
Reserved Oct 7, 2024

CISA Vulnrichment

Updated Oct 10, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Wordfence
Published Oct 10, 2024
Updated Apr 8, 2026

GitHub

No data