Query Shortcode
- <= 0.2.1
A local file inclusion vulnerability has been identified in the Query Shortcode plugin for WordPress, affecting all versions up to and including 0.2.1. The vulnerability arises in the shortcode function, allowing authenticated attackers with contributor-level access and above to include and execute arbitrary .php files on the server. This exploitation could bypass access controls, access sensitive data, or execute code in cases where .php files can be uploaded and included.
Exploitation of this vulnerability could lead to unauthorized file inclusion, allowing execution of malicious PHP code on the server.
No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.