The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/98d8c713-e8cd-4fad-a8fb-7a40db2742a2/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/98d8c713-e8cd-4fad-a8fb-7a40db2742a2/ | Exploit Third Party Advisory |
Configurations
History
12 May 2025, 19:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/98d8c713-e8cd-4fad-a8fb-7a40db2742a2/ - Exploit, Third Party Advisory | |
CWE | CWE-79 | |
First Time |
Getshortcodes
Getshortcodes shortcodes Ultimate |
|
CPE | cpe:2.3:a:getshortcodes:shortcodes_ultimate:*:*:*:*:*:wordpress:*:* |
21 Nov 2024, 09:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/98d8c713-e8cd-4fad-a8fb-7a40db2742a2/ - |
01 Aug 2024, 13:49
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
15 Apr 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-13 05:15
Updated : 2025-05-12 19:41
NVD link : CVE-2024-2583
Mitre link : CVE-2024-2583
CVE.ORG link : CVE-2024-2583
JSON object : View
Products Affected
getshortcodes
- shortcodes_ultimate
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')