Custom Content Shortcode <= 3.8.8 - Unauthorised Arbitrary Post Metadata Access
2022-02-02 00:00
Francesco CarlucciStrategic Overview
StatusPatched in 4.0.1
Affected PluginCustom Content Shortcode
Affected Version
<= 3.8.8CVSS4.3Medium
CVE
CVE-2021-24824Vulnerability Overview
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved
Technical Analysis
REMEDIATION: Update to version 4.0.1, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C