OSV 1.4.0 · unreviewed · 修改于 2026-09-01 17:31
发布时间
2026-09-01 17:31
GitHub 审查时间
—
NVD 发布时间
2026-09-01 16:17
源文件
advisories/unreviewed/2026/09/GHSA-224h-2cg4-2prq/GHSA-224h-2cg4-2prq.json
The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. Exploitation requires the site to have been configured to echo a submitted value back to the visitor after submission.
该公告没有提供结构化的受影响软件包信息。