plugin

Wc Shortcodes Vulnerabilities

8 known security issues reported for the Wc Shortcodes WordPress plugin. Most recent disclosed Dec 9, 2024.

1 high 2 medium

Running Wc Shortcodes on your site? Check whether your installed version is affected.

Scan your site free

Shortcodes by Angie Makes [wc-shortcodes] <= 3.46 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Chris Baldelomar Shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes: from n/a through 3.46.

Affected:
up to 3.46
Fix:
No patched version reported
Disclosed:
Dec 9, 2024

CVE-2023-23725 on NVD →

Shortcodes by Angie Makes <= 3.46 - Missing Authorization

medium

The Shortcodes by Angie Makes plugin for WordPress is vulnerable to missing authorization due to a missing capability check on one of its functions in versions up to, and including, 3.46. This makes it possible for unauthenticated attackers to invoke this function.

CVSS:
5.3
Affected:
up to 3.46
Fix:
No patched version reported
Disclosed:
Apr 14, 2023

CVE-2023-23725 on NVD →

Shortcodes by Angie Makes [wc-shortcodes] <= 1.67 (unfixed + closed)

unknown

[en] The Galleries by Angie Makes WordPress plugin through 1.67 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 1.67
Fix:
No patched version reported
Disclosed:
Feb 27, 2023

CVE-2022-4795 on NVD →

Galleries by Angie Makes <= 1.67 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Galleries by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.67 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...

CVSS:
6.4
Affected:
up to 1.67
Fix:
No patched version reported
Disclosed:
Feb 2, 2023

CVE-2022-4795 on NVD →

Shortcodes by Angie Makes < 2.07 - Authenticated Stored Cross-Site Scripting

high

The Shortcodes by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wc_button’ parameter in versions before 2.07 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers of Contributor-level or above to inject arbitrary web scrip...

CVSS:
7.4
Affected:
up to 2.07
Fixed in:
2.07
Disclosed:
Nov 19, 2016

Shortcodes by Angie Makes [wc-shortcodes] < 2.07 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 2.07
Fixed in:
2.07
Disclosed:
Nov 19, 2016

Shortcodes by Angie Makes [wc-shortcodes] < 2.07 (closed)

unknown

The Shortcodes by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wc_button’ parameter in versions before 2.07 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers of Contributor-level or above to inject arbitrary web scrip...

Affected:
up to 2.07
Fixed in:
2.07
Disclosed:
Nov 19, 2016

Shortcodes by Angie Makes [wc-shortcodes] < 2.07 (closed)

unknown
Affected:
up to 2.07
Fixed in:
2.07

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database