Shortcode Addons <= 3.2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- CVSS:
- 4.4
- Affected:
- up to 3.2.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2024
CVE-2024-37121 on NVD →
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
critical
The Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.2.5. This makes it possible for authenticated attackers, with administrator-level access and a...
- CVSS:
- 9.1
- Affected:
- up to 3.2.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 29, 2024
CVE-2024-31114 on NVD →
Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension <= 3.1.2 - Authenticated Arbitrary Options Update
high
The "Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension" plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including, 3.1.2. This makes it possible for authenticated attackers to modify arbitrary site options that can be used for complete site takeov...
- CVSS:
- 7.2
- Affected:
- up to 3.1.2
- Fixed in:
- 3.2.0
- Disclosed:
- Jul 25, 2022
CVE-2022-33970 on NVD →
Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension <= 3.0.2 - Unauthenticated Arbitrary Options Update
critical
The "Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension" plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including, 3.0.2. This is due to improperly configured capability checking via the permission_callback on the ShortCodeAddonsUltimate/v2/ REST...
- CVSS:
- 9.8
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Jun 30, 2022
CVE-2022-34487 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database