plugin

Olevmedia Shortcodes Vulnerabilities

9 known security issues reported for the Olevmedia Shortcodes WordPress plugin. Most recent disclosed May 3, 2023.

1 high 2 medium

Running Olevmedia Shortcodes on your site? Check whether your installed version is affected.

Scan your site free

Olevmedia Shortcodes [olevmedia-shortcodes] <= 1.1.9 (unfixed + closed)

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <= 1.1.9 versions.

Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
May 3, 2023

CVE-2023-25798 on NVD →

Olevmedia Shortcodes [olevmedia-shortcodes] <= 1.1.9 (unfixed + closed)

unknown

[en] The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Feb 27, 2023

CVE-2023-0168 on NVD →

Olevmedia Shortcodes <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Feb 15, 2023

CVE-2023-25798 on NVD →

Olevmedia Shortcodes [olevmedia-shortcodes] <= 1.1.9 (unfixed + closed)

unknown

Deactivate and delete. This plugin has been closed as of January 18, 2023 and is not available for download. This closure is temporary, pending a full review. Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Olevmedia Shortcodes Plugin. This could allow a malicious actor to inj...

Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Jan 27, 2023

Olevmedia Shortcodes <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

high

The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [button] shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor leve...

CVSS:
7.4
Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Jan 26, 2023

CVE-2023-0168 on NVD →

Olevmedia Shortcodes [olevmedia-shortcodes] <= 1.1.9 (unfixed + closed)

unknown

The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [button] shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor leve...

Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Jan 26, 2023

Olevmedia Shortcodes [olevmedia-shortcodes] < 1.1.9 (closed)

unknown

[en] The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Sep 26, 2019

CVE-2015-9421 on NVD →

Olevmedia Shortcodes <= 1.1.8 - Reflected Cross-Site Scripting

medium

The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.

CVSS:
6.1
Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Aug 25, 2015

CVE-2015-9421 on NVD →

Olevmedia Shortcodes [olevmedia-shortcodes] < 1.1.9 (closed)

unknown

Because of this vulnerability, authenticated users can inject HTML or JS code via "id" parameter. Update the plugin.

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Aug 25, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database