cleantalk
Vulnerabilities and Security Researches

Geo Controller, CVE-2024-7381

CVE, Research URL

CVE-2024-7381

Application

Geo Controller

Published on
Sep 05, 2024
Research Description
The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.
Affected versions
max 8.7.0.
Status
vulnerable