What the vulnerability does
01Description
Missing Authorization vulnerability in Tyche Softwares Arconix Shortcodes allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Arconix Shortcodes: from n/a through 2.1.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Tyche Softwares Arconix Shortcodes allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Arconix Shortcodes: from n/a through 2.1.11.
Explanation of Vulnerability in Simple Terms
Arconix Shortcodes through version 2.1.11 lacks proper authorization checks, allowing unauthenticated attackers to modify site content through the plugin's shortcode functionality. The vulnerability requires no user interaction and can be exploited over the network. Site administrators should update to a version newer than 2.1.11 to prevent unauthorized content changes.
What an attacker can do
Modify site content without authentication by exploiting missing authorization in shortcode processing.
Potential impact on your site
Attackers can alter published content, pages, or posts without logging in, potentially defacing your site.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities