CVE-2023-1273
Published: 04 July 2023
Summary
CVE-2023-1273 is a high-severity an unspecified weakness vulnerability in Nicdark Nd Shortcodes. Its CVSS base score is 8.8 (High).
Operationally, ranked in the top 5.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Deeper analysis
The ND Shortcodes WordPress plugin before version 7.0 contains a vulnerability in which certain shortcode attributes are not validated prior to being used to construct file paths passed to PHP include functions. This flaw affects any site running the plugin and enables local file inclusion.
Any authenticated user, including those with the subscriber role, can supply crafted shortcode parameters to trigger the LFI condition. Successful exploitation can result in arbitrary file reads or other impacts consistent with the reported CVSS 3.1 score of 8.8.
The referenced WPScan advisory at https://wpscan.com/vulnerability/0805ed7e-395d-48de-b484-6c3ec1cd4b8e documents the issue but provides no additional mitigation details beyond the version constraint. The associated EPSS score has remained flat at 0.1276 with no observed rise after disclosure.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-23540
Vulnerability details
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.