CVE-2024-8478 describes an arbitrary shortcode execution vulnerability in the Affiliate Super Assistent plugin for WordPress, affecting all versions up to and including 1.5.3. This high-severity vulnerability (CVSS 7.3) allows unauthenticated attackers to execute arbitrary shortcodes by submitting them in comments when the 'Parse comments' option is enabled. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the potential impact includes low confidentiality, integrity, and availability. Organizations using this plugin should update immediately or disable the 'Parse comments' option to mitigate risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.4CPE matchmatch criteria | cpe:2.3:a:ifeelweb:affiliate_super_assistent:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.