Description
WordPress Plugin Shortcode Addons-with Visual Composer, Divi, Beaver Builder and Elementor Extension is prone to a function injection vulnerability. An attacker may leverage this issue to call any static method, with up to three optional parameters. WordPress Plugin Shortcode Addons-with Visual Composer, Divi, Beaver Builder and Elementor Extension version 3.2.5 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin MM Forms Community 'edit_details.php' SQL Injection (1.2.3)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-4721)
PHP CVE-2004-1064 Vulnerability (CVE-2004-1064)
WordPress Plugin WordPress Download Manager Unspecified Vulnerability (2.9.96)
WordPress Plugin Lightweight Accordion Cross-Site Scripting (1.5.14)