CVE Database /
CVE-2017-2245
CVE · Medium
CVE-2017-2245 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 4.10.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-2245
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 4.10.0 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
5.0
|
< 4.10.0
|
4.10.0 |
2017-06-23 |
—
|
CVE-2017-2245
Versions before 4.10.0 of the Shortcodes Ultimate plugin are susceptible to a directory traversal flaw on the Examples page, allowing attackers to access files outside the intended directory. This vulnerability, identified by Chris Liu and reported through the Information Security Early Warning Partnership, was coordinated with the developer by JPCERT/CC. The issue stems from improper path validation when handling file requests within the plugin's example functionality.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings