Vulnerabilities > Gonahkar

DATE CVE VULNERABILITY TITLE RISK
2024-03-13 CVE-2023-6809 Cross-site Scripting vulnerability in Gonahkar Custom Fields Shortcode 0.1
The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied custom post meta values.
network
low complexity
gonahkar CWE-79
5.4