What the vulnerability does
01Description
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
Explanation of Vulnerability in Simple Terms
The Shortcode Addons WordPress plugin version 3.0.2 and earlier contains a critical vulnerability that allows unauthenticated attackers to read sensitive data, modify site content, and disrupt service without any user interaction. The plugin fails to properly restrict access to its core functions, exposing the site to complete compromise. All users should update immediately.
What an attacker can do
Read sensitive data, modify or delete content, and disable the site without authentication.
Potential impact on your site
Complete site compromise: attackers can steal data, deface content, and take the site offline.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities