VYPR

Nite Shortcodes

by WordPress

Source repositories

CVEs (3)

  • CVE-2025-23877MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nitethemes Nite Shortcodes nite-shortcodes allows Stored XSS.This issue affects Nite Shortcodes: from n/a through <= 1.0.

  • CVE-2023-1273Jul 4, 2023
    risk 0.01cvss epss 0.02

    The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks

  • CVE-2022-4623Jul 4, 2023
    risk 0.00cvss epss 0.00

    The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site…