Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 7.3.3
- Fixed in:
- 7.3.4
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_box Shortcode
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...
- CVSS:
- 6.4
- Affected:
- up to 7.4.9
- Fixed in:
- 7.5.0
- Disclosed:
- Apr 15, 2026
CVE-2026-3885 on NVD →
Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' Shortcode
medium
The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field. This makes it possi...
- CVSS:
- 6.4
- Affected:
- up to 7.4.8
- Fixed in:
- 7.4.9
- Disclosed:
- Apr 3, 2026
CVE-2026-0738 on NVD →
Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lightbox' Shortcode
medium
The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitization and output escaping in the 'src' attribute of the su_lightbox shortcode. This makes it possible for authenticated a...
- CVSS:
- 6.4
- Affected:
- up to 7.4.7
- Fixed in:
- 7.4.8
- Disclosed:
- Apr 3, 2026
CVE-2026-0737 on NVD →
Shortcodes Ultimate - WordPress WP Shortcodes Plugin - Shortcodes Ultimate plugin <= 7.4.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'max_width' Shortcode Attribute vulnerability
medium
WordPress WP Shortcodes Plugin - Shortcodes Ultimate plugin <= 7.4.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'max_width' Shortcode Attribute vulnerability
- CVSS:
- 6.5
- Affected:
- up to 7.4.10
- Fixed in:
- 7.5.0
- Disclosed:
- Apr 1, 2026
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'max_width' Shortcode Attribute
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the `su_box` shortcode in all versions up to, and including, 7.4.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss...
- CVSS:
- 6.4
- Affected:
- up to 7.4.10
- Fixed in:
- 7.5.0
- Disclosed:
- Mar 31, 2026
CVE-2026-2480 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.5 - Authenticated (Administrator+) Server-Side Request Forgery
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via the su_shortcode_csv_table function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arb...
- CVSS:
- 6.4
- Affected:
- up to 7.4.5
- Fixed in:
- 7.4.6
- Disclosed:
- Nov 23, 2025
CVE-2025-12800 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.4.6
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via the su_shortcode_csv_table function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests t...
- Affected:
- up to 7.4.6
- Fixed in:
- 7.4.6
- Disclosed:
- Nov 23, 2025
CVE-2025-12800 on NVD →
Shortcodes Ultimate <= 7.4.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title and Slide Link
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 7.4.2
- Fixed in:
- 7.4.3
- Disclosed:
- Jul 21, 2025
CVE-2025-8015 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 7.4.2
- Fixed in:
- 7.4.3
- Disclosed:
- Jul 20, 2025
CVE-2025-7354 on NVD →
Shortcodes Ultimate <= 7.4.2 - Cross-Site Request Forgery to Arbitrary Shortcode Execution
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This is due to missing or incorrect nonce validation on the preview function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes...
- CVSS:
- 6.1
- Affected:
- up to 7.4.2
- Fixed in:
- 7.4.3
- Disclosed:
- Jul 20, 2025
CVE-2025-7369 on NVD →
Shortcodes Ultimate <= 7.4.0 - Authenticted (Contributor+) Stored Cross-Site Scripting via 'data-url' Attribute
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-url' DOM element attribute in all versions up to, and including, 7.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contr...
- CVSS:
- 6.4
- Affected:
- up to 7.4.0
- Fixed in:
- 7.4.1
- Disclosed:
- Jul 3, 2025
CVE-2025-5567 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 7.4.2
- Fixed in:
- 7.4.3
- Disclosed:
- Jul 2, 2025
CVE-2024-5647 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.4.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vova Shortcodes Ultimate allows Stored XSS. This issue affects Shortcodes Ultimate: from n/a through 7.3.5.
- Affected:
- up to 7.4.0
- Fixed in:
- 7.4.0
- Disclosed:
- Jun 6, 2025
CVE-2025-49244 on NVD →
Shortcodes Ultimate <= 7.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pa...
- CVSS:
- 6.4
- Affected:
- up to 7.3.5
- Fixed in:
- 7.4.0
- Disclosed:
- Jun 5, 2025
CVE-2025-49244 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via src Parameter
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acce...
- CVSS:
- 6.4
- Affected:
- up to 7.3.3
- Fixed in:
- 7.3.4
- Disclosed:
- Mar 3, 2025
CVE-2025-0370 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.3.0
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le...
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
- Disclosed:
- Oct 23, 2024
CVE-2024-8500 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a...
- CVSS:
- 5.4
- Affected:
- up to 7.2.2
- Fixed in:
- 7.3.0
- Disclosed:
- Oct 22, 2024
CVE-2024-8500 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.1.7
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up to, and including, 7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- Affected:
- up to 7.1.7
- Fixed in:
- 7.1.7
- Disclosed:
- Jun 5, 2024
CVE-2024-4821 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_lightbox Shortcode
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up to, and including, 7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- CVSS:
- 6.4
- Affected:
- up to 7.1.6
- Fixed in:
- 7.1.7
- Disclosed:
- Jun 4, 2024
CVE-2024-4821 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.1.6
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_members' shortcode in all versions up to, and including, 7.1.5 due to insufficient input sanitization and output escaping on user supplied 'color' attribute. This makes it possible...
- Affected:
- up to 7.1.6
- Fixed in:
- 7.1.6
- Disclosed:
- May 21, 2024
CVE-2024-4553 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_members Shortcode
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_members' shortcode in all versions up to, and including, 7.1.5 due to insufficient input sanitization and output escaping on user supplied 'color' attribute. This makes it possible for a...
- CVSS:
- 6.4
- Affected:
- up to 7.1.5
- Fixed in:
- 7.1.6
- Disclosed:
- May 20, 2024
CVE-2024-4553 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.12.7
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vova Anokhin Shortcodes Ultimate allows Absolute Path Traversal.This issue affects Shortcodes Ultimate: from n/a through 5.12.6.
- Affected:
- up to 5.12.7
- Fixed in:
- 5.12.7
- Disclosed:
- May 17, 2024
CVE-2023-25050 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.1.2
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.2
- Disclosed:
- May 15, 2024
CVE-2024-3548 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.1.2
unknown
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.2
- Disclosed:
- May 9, 2024
CVE-2024-4542 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.1.3
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 7.1.3
- Fixed in:
- 7.1.3
- Disclosed:
- May 2, 2024
CVE-2024-3550 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.3
- Disclosed:
- Apr 29, 2024
CVE-2024-3550 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.1.0
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting atta...
- Affected:
- up to 7.1.0
- Fixed in:
- 7.1.0
- Disclosed:
- Apr 26, 2024
CVE-2024-3188 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_lightbox
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- CVSS:
- 6.4
- Affected:
- up to 7.1.0
- Fixed in:
- 7.1.2
- Disclosed:
- Apr 24, 2024
CVE-2024-3548 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.0.5
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.
- Affected:
- up to 7.0.5
- Fixed in:
- 7.0.5
- Disclosed:
- Apr 13, 2024
CVE-2024-2583 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.0.5
unknown
- Affected:
- up to 7.0.5
- Fixed in:
- 7.0.5
- Disclosed:
- Apr 9, 2024
CVE-2024-3512 on NVD →
Shortcodes Ultimate <= 7.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_dailymotion shortcode in all versions, up to and including 7.0.5, due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...
- CVSS:
- 6.4
- Affected:
- up to 7.0.5
- Fixed in:
- 7.1.0
- Disclosed:
- Apr 5, 2024
CVE-2024-3188 on NVD →
Shortcodes Ultimate <= 7.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_color' Shortcode
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'note_color' shortcode in all versions up to, and including, 7.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...
- CVSS:
- 6.4
- Affected:
- up to 7.0.4
- Fixed in:
- 7.0.5
- Disclosed:
- Mar 23, 2024
CVE-2024-2583 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.0.4
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- Affected:
- up to 7.0.4
- Fixed in:
- 7.0.4
- Disclosed:
- Feb 28, 2024
CVE-2024-1808 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_qrcode Shortcode
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- CVSS:
- 6.4
- Affected:
- up to 7.0.3
- Fixed in:
- 7.0.4
- Disclosed:
- Feb 27, 2024
CVE-2024-1808 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.0.3
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping on user supplied attributes and user supplied tags. This make...
- Affected:
- up to 7.0.3
- Fixed in:
- 7.0.3
- Disclosed:
- Feb 20, 2024
CVE-2024-1510 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.0.2
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping on RSS feed content. This makes it possible for authenticated attacke...
- Affected:
- up to 7.0.2
- Fixed in:
- 7.0.2
- Disclosed:
- Feb 20, 2024
CVE-2024-0792 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_tooltip Shortcode
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping on user supplied attributes and user supplied tags. This makes it...
- CVSS:
- 6.4
- Affected:
- up to 7.0.2
- Fixed in:
- 7.0.3
- Disclosed:
- Feb 19, 2024
CVE-2024-1510 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping on RSS feed content. This makes it possible for authenticated attackers wi...
- CVSS:
- 6.4
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.2
- Disclosed:
- Feb 7, 2024
CVE-2024-0792 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.0.1
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. T...
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.1
- Disclosed:
- Dec 19, 2023
CVE-2023-6488 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This m...
- CVSS:
- 5.4
- Affected:
- up to 7.0.0
- Fixed in:
- 7.0.1
- Disclosed:
- Dec 18, 2023
CVE-2023-6488 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.0.0
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'. This makes it possible for authenticated attackers,...
- Affected:
- up to 7.0.0
- Fixed in:
- 7.0.0
- Disclosed:
- Nov 28, 2023
CVE-2023-6226 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.0.0
unknown
[en] The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This...
- Affected:
- up to 7.0.0
- Fixed in:
- 7.0.0
- Disclosed:
- Nov 28, 2023
CVE-2023-6225 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 5.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This make...
- CVSS:
- 6.4
- Affected:
- up to 5.13.3
- Fixed in:
- 7.0.0
- Disclosed:
- Nov 27, 2023
CVE-2023-6225 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate <= 5.13.3 - Insecure Direct Object Reference to Information Disclosure
medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 5.13.3
- Fixed in:
- 7.0.0
- Disclosed:
- Nov 27, 2023
CVE-2023-6226 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.12.7
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.
- Affected:
- up to 5.12.7
- Fixed in:
- 5.12.7
- Disclosed:
- Nov 13, 2023
CVE-2023-23800 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 5.12.5 – 5.13.0
- Fixed in:
- 5.13.1
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.12.7
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin — Shortcodes Ultimate plugin <= 5.12.6 versions.
- Affected:
- up to 5.12.7
- Fixed in:
- 5.12.7
- Disclosed:
- Mar 30, 2023
CVE-2023-25040 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.12.8
unknown
[en] The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password prot...
- Affected:
- up to 5.12.8
- Fixed in:
- 5.12.8
- Disclosed:
- Mar 20, 2023
CVE-2023-0890 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.12.8
unknown
[en] The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by defau...
- Affected:
- up to 5.12.8
- Fixed in:
- 5.12.8
- Disclosed:
- Mar 20, 2023
CVE-2023-0911 on NVD →
Shortcodes Ultimate <= 5.12.7 - Authenticated (Subscriber+) Information Exposure
medium
The Shortcodes Ultimate for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.12.7 via its shortcodes. This can allow authenticated attackers with subscriber-level privileges or higher to extract sensitive data including user meta information.
- CVSS:
- 6.5
- Affected:
- up to 5.12.7
- Fixed in:
- 5.12.8
- Disclosed:
- Feb 27, 2023
CVE-2023-0911 on NVD →
Shortcodes Ultimate <= 5.12.7 - Authenticated (Subscriber+) Arbitrary Post Access via Shortcode
medium
The Shortcodes Ultimate plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization controls in a plugin's shortcode in versions up to, and including, 5.12.7. This makes it possible for authenticated attackers with subscriber-level permissions and above to read arbitrary posts.
- CVSS:
- 4.3
- Affected:
- up to 5.12.7
- Fixed in:
- 5.12.8
- Disclosed:
- Feb 27, 2023
CVE-2023-0890 on NVD →
Shortcodes Ultimate <= 5.12.6 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.12.6. This is due to insufficient validation on the url being supplied via the "url" attribute of the su_csv_table shortcode. This makes it possible for authenticated attackers, with subscriber-...
- CVSS:
- 6.5
- Affected:
- up to 5.12.6
- Fixed in:
- 5.12.7
- Disclosed:
- Feb 10, 2023
CVE-2023-23800 on NVD →
Shortcodes Ultimate <= 5.12.6 - Authenticated (Subscriber+) Arbitrary File Read via Shortcode
medium
The Shortcodes Ultimate plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 5.12.6. This is due to insufficient validation on the url being supplied via the "url" attribute of the su_table shortcode. This makes it possible for authenticated attackers, with subscriber-level privil...
- CVSS:
- 6.5
- Affected:
- up to 5.12.6
- Fixed in:
- 5.12.7
- Disclosed:
- Feb 10, 2023
CVE-2023-25050 on NVD →
Shortcodes Ultimate <= 5.12.6 - Authenticated (Contributor+) Stored Cross Site Scripting
medium
The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 5.12.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor lev...
- CVSS:
- 6.4
- Affected:
- up to 5.12.6
- Fixed in:
- 5.12.7
- Disclosed:
- Feb 10, 2023
CVE-2023-25040 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.12.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
- Affected:
- up to 5.12.1
- Fixed in:
- 5.12.1
- Disclosed:
- Nov 8, 2022
CVE-2022-41136 on NVD →
Shortcodes Ultimate <= 5.12.0 - Cross-Site Request Forgery
high
The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.12.0. This is due to missing nonce validation on the ajax_add_preset() function. This makes it possible for unauthenticated attackers to make preset changes and inject malicious JavaScript via a...
- CVSS:
- 8.8
- Affected:
- up to 5.12.0
- Fixed in:
- 5.12.1
- Disclosed:
- Oct 13, 2022
CVE-2022-41136 on NVD →
Shortcodes Ultimate <= 5.12.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘settings’ parameter saved via the ajax_add_preset() function in versions up to, and including, 5.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with su...
- CVSS:
- 6.4
- Affected:
- up to 5.12.0
- Fixed in:
- 5.12.1
- Disclosed:
- Oct 13, 2022
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.12.1
unknown
The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘settings’ parameter saved via the ajax_add_preset() function in versions up to, and including, 5.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with su...
- Affected:
- up to 5.12.1
- Fixed in:
- 5.12.1
- Disclosed:
- Oct 13, 2022
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.12.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change.
- Affected:
- up to 5.12.1
- Fixed in:
- 5.12.1
- Disclosed:
- Oct 11, 2022
CVE-2022-38086 on NVD →
Shortcodes Ultimate <= 5.12.0 - Cross-Site Request Forgery
high
The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.12.0. This is due to missing or incorrect nonce validation on the ajax_remove_preset() and ajax_get_preset() functions. This makes it possible for unauthenticated attackers to make preset changes...
- CVSS:
- 8.8
- Affected:
- up to 5.12.0
- Fixed in:
- 5.12.1
- Disclosed:
- Oct 2, 2022
CVE-2022-38086 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.10.2
unknown
[en] The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_b...
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.2
- Disclosed:
- Sep 20, 2021
CVE-2021-24525 on NVD →
WordPress Shortcodes Plugin — Shortcodes Ultimate <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button...
- CVSS:
- 5.4
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.2
- Disclosed:
- Aug 23, 2021
CVE-2021-24525 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.0.1
unknown
[en] The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
- Affected:
- up to 5.0.1
- Fixed in:
- 5.0.1
- Disclosed:
- Aug 22, 2019
CVE-2017-18580 on NVD →
WordPress Shortcodes Plugin — Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution
high
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
- CVSS:
- 8.8
- Affected:
- up to 5.0.1
- Fixed in:
- 5.0.1
- Disclosed:
- Oct 31, 2017
CVE-2017-18580 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 4.10.0
unknown
[en] Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.
- Affected:
- up to 4.10.0
- Fixed in:
- 4.10.0
- Disclosed:
- Jul 7, 2017
CVE-2017-2245 on NVD →
WordPress Shortcodes Plugin — Shortcodes Ultimate < 4.10.0 - Directory Traversal
medium
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.
- CVSS:
- 5
- Affected:
- up to 4.10.0
- Fixed in:
- 4.10.0
- Disclosed:
- Jun 23, 2017
CVE-2017-2245 on NVD →
WordPress Shortcodes Plugin — Shortcodes Ultimate <= 4.9.3 - Cross-Site Scripting
medium
The WordPress Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.1
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.4
- Disclosed:
- May 5, 2015
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 4.9.4
unknown
The WordPress Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.4
- Disclosed:
- May 5, 2015
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.3.4
unknown
- Affected:
- up to 7.3.4
- Fixed in:
- 7.3.4
CVE-2025-0370 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] <= 7.4.2 (unfixed)
unknown
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 7.4.2
- Fix:
- No patched version reported
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.4.1
unknown
- Affected:
- up to 7.4.1
- Fixed in:
- 7.4.1
CVE-2025-5567 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.4.3
unknown
- Affected:
- up to 7.4.3
- Fixed in:
- 7.4.3
CVE-2025-7369 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.4.3
unknown
- Affected:
- up to 7.4.3
- Fixed in:
- 7.4.3
CVE-2025-7354 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.4.3
unknown
- Affected:
- up to 7.4.3
- Fixed in:
- 7.4.3
CVE-2025-8015 on NVD →
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 5.13.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 5.13.1
- Fixed in:
- 5.13.1
CVE-2023-33999 on NVD →