CVE Database /
CVE-2023-25050
CVE · High
CVE-2023-25050 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-25050
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
7.1
|
< 5.12.7
|
5.12.7 |
2023-02-10 |
—
|
CVE-2023-25050
The Shortcodes Ultimate plugin through version 5.12.6 contains an arbitrary file read vulnerability in the su_table shortcode caused by inadequate validation of the url parameter. Authenticated users with subscriber access or higher can exploit this flaw to retrieve contents of arbitrary files, including sensitive configuration files such as wp-config.php, when the Unsafe features setting is activated. The vulnerability was patched in version 5.12.7.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings