CVE · High

CVE-2023-25050 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-25050 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.1 < 5.12.7 5.12.7 2023-02-10

CVE-2023-25050

The Shortcodes Ultimate plugin through version 5.12.6 contains an arbitrary file read vulnerability in the su_table shortcode caused by inadequate validation of the url parameter. Authenticated users with subscriber access or higher can exploit this flaw to retrieve contents of arbitrary files, including sensitive configuration files such as wp-config.php, when the Unsafe features setting is activated. The vulnerability was patched in version 5.12.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.