CVE-2021-24825
Last modified
CVE-2021-24825 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP files will be executed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when either the unfiltered_html or file_edit is disallowed). EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP files will be executed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when either the unfiltered_html or file_edit is disallowed)
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Custom Content Shortcode Project | Custom Content Shortcode | < 4.0.2 |
References
- https://wpscan.com/vulnerability/be9d6f82-c972-459a-bacf-65b3dfb11a09Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/be9d6f82-c972-459a-bacf-65b3dfb11a09Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-24825?
How severe is CVE-2021-24825?
How do I fix CVE-2021-24825?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-2482Vulnerability in the Oracle Payables product of Oracle E-Bus…8.1
- CVE-2021-24820The Cost Calculator WordPress plugin through 1.6 allows auth…6.5
- CVE-2021-24821The Cost Calculator WordPress plugin before 1.6 allows users…5.4
- CVE-2021-24822The Stylish Cost Calculator WordPress plugin before 7.0.4 do…5.4
- CVE-2021-24823The Support Board WordPress plugin before 3.3.6 does not hav…8.1
- CVE-2021-24824The [field] shortcode included with the Custom Content Short…4.3
- CVE-2021-24826The Custom Content Shortcode WordPress plugin before 4.0.2 d…5.4
- CVE-2021-24827The Asgaros Forum WordPress plugin before 1.15.13 does not v…9.8
- CVE-2021-24828The Mortgage Calculator / Loan Calculator WordPress plugin b…5.4
- CVE-2021-24829The Visitor Traffic Real Time Statistics WordPress plugin be…8.8
- CVE-2021-2483Vulnerability in the Oracle Content Manager product of Oracl…8.1
- CVE-2021-24830The Advanced Access Manager WordPress plugin before 6.8.0 do…4.8
Are you affected by CVE-2021-24825?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
