Shortcodes by Angie Makes [wc-shortcodes] <= 3.46 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Chris Baldelomar Shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes: from n/a through 3.46.
- Affected:
- up to 3.46
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2024
CVE-2023-23725 on NVD →
Shortcodes by Angie Makes <= 3.46 - Missing Authorization
medium
The Shortcodes by Angie Makes plugin for WordPress is vulnerable to missing authorization due to a missing capability check on one of its functions in versions up to, and including, 3.46. This makes it possible for unauthenticated attackers to invoke this function.
- CVSS:
- 5.3
- Affected:
- up to 3.46
- Fix:
- No patched version reported
- Disclosed:
- Apr 14, 2023
CVE-2023-23725 on NVD →
Shortcodes by Angie Makes [wc-shortcodes] <= 1.67 (unfixed + closed)
unknown
[en] The Galleries by Angie Makes WordPress plugin through 1.67 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 1.67
- Fix:
- No patched version reported
- Disclosed:
- Feb 27, 2023
CVE-2022-4795 on NVD →
Galleries by Angie Makes <= 1.67 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Galleries by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.67 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...
- CVSS:
- 6.4
- Affected:
- up to 1.67
- Fix:
- No patched version reported
- Disclosed:
- Feb 2, 2023
CVE-2022-4795 on NVD →
Shortcodes by Angie Makes < 2.07 - Authenticated Stored Cross-Site Scripting
high
The Shortcodes by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wc_button’ parameter in versions before 2.07 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers of Contributor-level or above to inject arbitrary web scrip...
- CVSS:
- 7.4
- Affected:
- up to 2.07
- Fixed in:
- 2.07
- Disclosed:
- Nov 19, 2016
Shortcodes by Angie Makes [wc-shortcodes] < 2.07 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 2.07
- Fixed in:
- 2.07
- Disclosed:
- Nov 19, 2016
Shortcodes by Angie Makes [wc-shortcodes] < 2.07 (closed)
unknown
The Shortcodes by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wc_button’ parameter in versions before 2.07 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers of Contributor-level or above to inject arbitrary web scrip...
- Affected:
- up to 2.07
- Fixed in:
- 2.07
- Disclosed:
- Nov 19, 2016
Shortcodes by Angie Makes [wc-shortcodes] < 2.07 (closed)
unknown
- Affected:
- up to 2.07
- Fixed in:
- 2.07
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database