Description
WordPress processes shortcodes in user-generated content on block themes. This could allow an attacker to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically require higher permissions. WordPress versions 6.1.x ranging from 6.1 and up to (and including) 6.1.2 are vulnerable.
Remediation
Update to WordPress version 6.1.3 or latest
References
Related Vulnerabilities
WordPress Plugin Software License Manager Cross-Site Request Forgery (4.4.5)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0185)
WordPress Plugin MC4WP:Mailchimp for WordPress Cross-Site Request Forgery (4.8.4)
Plone CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-28735)
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2017-8385)