CVE-2024-9578 Information
Nov 14, 2024
cve
Description
The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.
Reference
https://www.wordfence.com/threat-intel/vulnerabilities/id/4198bbb2-3aff-492e-a781-b0c9477baf6c?source=cve https://plugins.trac.wordpress.org/browser/hide-links/trunk/class.hidelinks.php#L21
Share on: