WordPress plugin Shortcode Addons <= 3.0.2 contains an unauthenticated arbitrary option update caused by insufficient access controls in the plugin, letting attackers modify options without authentication.
id: CVE-2022-34487
info:
name: ShortCode Addons - Unauthenticated Options Update
author: Sourab
...