CVE Published: 09/04/2024 |
CVE Updated: 08/08/2024 |
CVE Year: 2023 Source: Wordfence |
Vendor: sc0ttkclark |
Product: Pods – Custom Content Types and Fields Status : PUBLISHED
CVE-2023-6999 Description
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute code on the server.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H