VYPR

Shortcodes Ultimate

by Getshortcodes

Source repositories

CVEs (25)

  • CVE-2021-24525MedSep 20, 2021
    risk 0.35cvss 5.4epss 0.01

    The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes…

  • CVE-2017-2245MedJul 7, 2017
    risk 0.33cvss 5.0epss 0.03

    Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2024-4217MedJul 13, 2024
    risk 0.31cvss 4.7epss 0.00

    The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.

  • CVE-2024-8500MedOct 23, 2024
    risk 0.28cvss 5.4epss 0.00

    The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2023-6226MedNov 28, 2023
    risk 0.28cvss 4.3epss 0.01

    The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'. This makes it…

Page 2 of 2