Retour à la veille

CVE-2026-84744

Publié : 28 septembre 2026
Modifié : 28 septembre 2026
Lien officiel NVD
Score CVSS
6.5
MEDIUM

Description détaillée

The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Références et Patchs