The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
References
Configurations
No configuration.
History
08 Apr 2026, 18:19
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References |
|
|
04 Dec 2024, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-12-04 03:15
Updated : 2026-06-17 06:56
NVD link : CVE-2024-10952
Mitre link : CVE-2024-10952
CVE.ORG link : CVE-2024-10952
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
