plugin

Shortcode Factory Vulnerabilities

2 known security issues reported for the Shortcode Factory WordPress plugin. Most recent disclosed Jan 16, 2019.

1 critical 1 medium

Running Shortcode Factory on your site? Check whether your installed version is affected.

Scan your site free

Shortcode Factory <= 2.7 - Local File Inclusion

critical

The Shortcode Factory plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'ui' parameter found in the '/core/functions.php' file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in tho...

CVSS:
9.8
Affected:
up to 2.7
Fixed in:
2.8
Disclosed:
Jan 16, 2019

CVE-2019-15322 on NVD →

Shortcode Factory <= 1.1 - Reflected Cross-Site Scripting

medium

The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.

CVSS:
6.1
Affected:
up to 1.1
Fixed in:
1.1.1
Disclosed:
Apr 21, 2015

CVE-2015-9321 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database