Description
The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note that a nonce is used as authentication here, but the value is leaked. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's Shortcodes.
Problem types
Product status
* (semver)
Timeline
| 2024-12-11: | Disclosed |
Credits
Youcef Hamdani
References
www.wordfence.com/...-6977-478a-b62e-0ec9385eb2af?source=cve
wordpress.org/plugins/shortcode-variables/
plugins.trac.wordpress.org/...ables/trunk/includes/hooks.php