← Back to CVE List

CVE-2023-1273

Published: 2023-07-04T08:15Z
Last Modified: 2024-11-21T07:38Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks > MITRE Terms of Use apply – see LICENSE‑MITRE.txt