getshortcodes Vulnerabilities and Affected Products
Vulnerabilities associated with shortcodes_ultimate.
Products
Clear product- shortcodes_ultimate4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-4217MEDIUM | Shortcodes Ultimate Pro < 7.1.5 - Contributor+ Stored Cross-Site Scripting XSSThe shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks. CWE-79Jul 13, 2024 | CVSS4.7v3.1 | EPSS0.461% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3188MEDIUM | Shortcodes Ultimate < 7.1.0 - Contributor+ Stored XSSThe WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CWE-79Apr 26, 2024 | CVSS6.3v3.1 | EPSS0.438% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2583MEDIUM | Shortcodes Ultimate < 7.0.5 - Contributor+ Stored XSSThe WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks. CWE-79Apr 13, 2024 | CVSS5.4v3.1 | EPSS0.403% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-18580CRITICAL | getshortcodes shortcodes_ultimate Improper Input ValidationThe shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode. | CVSS9.8v3.0 | EPSS12.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |