plugin

Bootstrap Shortcodes Vulnerabilities

14 known security issues reported for the Bootstrap Shortcodes WordPress plugin. Most recent disclosed Feb 21, 2023.

12 medium

Running Bootstrap Shortcodes on your site? Check whether your installed version is affected.

Scan your site free

Bootstrap Shortcodes [bootstrap-shortcodes] <= 3.4.0 (unfixed + closed)

unknown

[en] The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Feb 21, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'id' parameters in the 'bs_dropdown' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbi...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in the 'bs_icon' shortcode in versions up to, and including, 3.4.0. This may make it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web sc...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the 'bs_notification' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary w...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' parameter in the 'bs_well' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'href' parameters in the 'bs_tab' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitra...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in the 'bs_row' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in the 'bs_col' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the 'bs_tcontent' shortcode in versions up to, and including, 3.4.0. This may make it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the 'bs_label' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scri...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size', 'type', and 'href' parameters in the 'bs_button' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inj...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

CVE-2022-4777 on NVD →

Bootstrap Shortcodes [bootstrap-shortcodes] <= 3.4.0 (unfixed + closed)

unknown

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'id' parameters in the 'bs_dropdown' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbi...

Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'parent' parameters in the 'bs_citem' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitr...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 26, 2023

CVE-2022-4777 on NVD →

BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the 'bs_collapse' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 3.4.0
Fix:
No patched version reported
Disclosed:
Jan 26, 2023

CVE-2022-4777 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database