CVE-2024-12018: Snippet Shortcodes <= 4.1.6 - Authenticated (Subscriber+) Shortcode Deletion

4.3 CVSS

Description

The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note that a nonce is used as authentication here, but the value is leaked. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's Shortcodes.

Classification

CVE ID: CVE-2024-12018

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.3

Affected Products

Vendor: aliakro

Product: Snippet Shortcodes

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 23.99% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/4e6e8f68-6977-478a-b62e-0ec9385eb2af?source=cve
https://wordpress.org/plugins/shortcode-variables/
https://plugins.trac.wordpress.org/changeset/3205481/shortcode-variables/trunk/includes/hooks.php

Timeline