Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48317 | The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site. |
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 06 Sep 2024 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Infinitumform
Infinitumform geo Controller |
|
| CPEs | cpe:2.3:a:infinitumform:geo_controller:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Infinitumform
Infinitumform geo Controller |
Thu, 05 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress geo Controller |
|
| CPEs | cpe:2.3:a:wordpress:geo_controller:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Wordpress
Wordpress geo Controller |
|
| Metrics |
ssvc
|
Thu, 05 Sep 2024 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site. | |
| Title | Geo Controller <= 8.6.9 - Missing Authorization to Unauthenticated Shortcode Execution | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:51:54.412Z
Reserved: 2024-08-01T13:13:17.911Z
Link: CVE-2024-7381
Updated: 2024-09-05T18:11:25.373Z
Status : Modified
Published: 2024-09-05T11:15:13.043
Modified: 2026-04-08T18:22:31.393
Link: CVE-2024-7381
No data.
OpenCVE Enrichment
No data.
EUVD