VYPR

Themify Shortcodes

by WordPress

Source repositories

CVEs (2)

  • CVE-2024-4567MedMay 14, 2024
    risk 0.35cvss 6.4epss 0.00

    The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2022-4787Jan 30, 2023
    risk 0.00cvss epss 0.00

    Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.