Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-7381

The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 76.7%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2024-7381


Contact Us

Shodan ® - All rights reserved