Showing 4 vulnerabilities on this page for shortcodes_ultimate

Signals CISA KEV Ransomware Nuclei
getshortcodes vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Shortcodes Ultimate Pro < 7.1.5 - Contributor+ Stored Cross-Site Scripting XSS

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.

CWE-79Jul 13, 2024
CVSS4.7v3.1EPSS0.461%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Shortcodes Ultimate < 7.1.0 - Contributor+ Stored XSS

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CWE-79Apr 26, 2024
CVSS6.3v3.1EPSS0.438%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Shortcodes Ultimate < 7.0.5 - Contributor+ Stored XSS

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.

CWE-79Apr 13, 2024
CVSS5.4v3.1EPSS0.403%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

getshortcodes shortcodes_ultimate Improper Input Validation

The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.

CWE-20Aug 22, 20191 related artifact
CVSS9.8v3.0EPSS12.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX