Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49210 | The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 27 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:webliberty:simple_spoiler:*:*:*:*:*:wordpress:*:* |
Tue, 17 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webliberty
Webliberty simple Spoiler |
|
| CPEs | cpe:2.3:a:webliberty:simple_spoiler:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webliberty
Webliberty simple Spoiler |
|
| Metrics |
ssvc
|
Sat, 14 Sep 2024 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | |
| Title | Simple Spoiler 1.2 - 1.3 - Unauthenticated Arbitrary Shortcode Execution | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-09-16T19:11:05.482Z
Reserved: 2024-09-05T15:17:31.811Z
Link: CVE-2024-8479
Updated: 2024-09-16T19:10:56.276Z
Status : Analyzed
Published: 2024-09-14T04:15:04.733
Modified: 2024-09-27T16:12:10.427
Link: CVE-2024-8479
No data.
OpenCVE Enrichment
No data.
EUVD