Olevmedia Shortcodes [olevmedia-shortcodes] <= 1.1.9 (unfixed + closed)
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <= 1.1.9 versions.
- Affected:
- up to 1.1.9
- Fix:
- No patched version reported
- Disclosed:
- May 3, 2023
CVE-2023-25798 on NVD →
Olevmedia Shortcodes [olevmedia-shortcodes] <= 1.1.9 (unfixed + closed)
unknown
[en] The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 1.1.9
- Fix:
- No patched version reported
- Disclosed:
- Feb 27, 2023
CVE-2023-0168 on NVD →
Olevmedia Shortcodes <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 1.1.9
- Fix:
- No patched version reported
- Disclosed:
- Feb 15, 2023
CVE-2023-25798 on NVD →
Olevmedia Shortcodes [olevmedia-shortcodes] <= 1.1.9 (unfixed + closed)
unknown
Deactivate and delete. This plugin has been closed as of January 18, 2023 and is not available for download. This closure is temporary, pending a full review.
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Olevmedia Shortcodes Plugin. This could allow a malicious actor to inj...
- Affected:
- up to 1.1.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
Olevmedia Shortcodes <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
high
The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [button] shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor leve...
- CVSS:
- 7.4
- Affected:
- up to 1.1.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 26, 2023
CVE-2023-0168 on NVD →
Olevmedia Shortcodes [olevmedia-shortcodes] <= 1.1.9 (unfixed + closed)
unknown
The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [button] shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor leve...
- Affected:
- up to 1.1.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 26, 2023
Olevmedia Shortcodes [olevmedia-shortcodes] < 1.1.9 (closed)
unknown
[en] The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- Sep 26, 2019
CVE-2015-9421 on NVD →
Olevmedia Shortcodes <= 1.1.8 - Reflected Cross-Site Scripting
medium
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- Aug 25, 2015
CVE-2015-9421 on NVD →
Olevmedia Shortcodes [olevmedia-shortcodes] < 1.1.9 (closed)
unknown
Because of this vulnerability, authenticated users can inject HTML or JS code via "id" parameter.
Update the plugin.
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- Aug 25, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database