CVE-2021-24824 Information
Jun 07, 2022
cve
Description
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1 allows authenticated users with a role as low as contributor to access arbitrary post metadata. This could lead to sensitive data disclosure for example when used in combination with WooCommerce the email address of orders can be retrieved
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://wpscan.com/vulnerability/7b4d4675-6089-4435-9b56-31496adc4767
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: