cve/2024/CVE-2024-1687.md
2024-05-25 21:48:12 +02:00

979 B
Raw Permalink Blame History

CVE-2024-1687

Description

The Thank You Page Customizer for WooCommerce Increase Your Sales plugin for WordPress is vulnerable to unauthorized execution of shortcodes due to a missing capability check on the get_text_editor_content() function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

POC

Reference

No PoCs from references.

Github