WordPress Plugin Vulnerabilities

Shortcodes Ultimate <= 5.0.0 - Authenticated Contributor Code Execution

Description

The Shortcodes Ultimate plugin does not sanitize the "filter" argument to the "su_meta", "su_user", and "su_post" shortcodes, allowing the filter to be set to the "system()" function which runs arbitrary code.

This is being exploited in the wild; I discovered this though analysis of mod_security audit logs on two compromised sites today.

Proof of Concept

Affects Plugins

Fixed in 5.0.1

References

Classification

Miscellaneous

Submitter
Robert Mathews
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2017-10-31 (about 8 years ago)
Added
2017-11-07 (about 8 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other