Description
WordPress Plugin Shortcode Addons-with Visual Composer, Divi, Beaver Builder and Elementor Extension is prone to a function injection vulnerability. An attacker may leverage this issue to call any static method, with up to three optional parameters. WordPress Plugin Shortcode Addons-with Visual Composer, Divi, Beaver Builder and Elementor Extension version 3.2.5 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WPFront Notification Bar Cross-Site Scripting (1.9.1.04012)
WordPress Plugin Image Optimizer, Resizer and CDN-Sirv Arbitrary File Upload (7.2.6)
Contao Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10642)
WordPress Plugin Facebook, Twitter & Google+ Social Widgets Multiple Vulnerabilities (1.3.7)
WordPress Plugin PHPFreeChat 'url' Parameter Cross-Site Scripting (0.2.8)