cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forshortcodes-ultimate shortcodes-ultimate

Direction: ascending
Jun 07, 2024

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2022-41136

CVE, Research URL

CVE-2022-41136

Date
Nov 09, 2022
Research Description
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2023-25050

CVE, Research URL

CVE-2023-25050

Date
May 17, 2024
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vova Anokhin Shortcodes Ultimate allows Absolute Path Traversal.This issue affects Shortcodes Ultimate: from n/a through 5.12.6.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2021-24525

CVE, Research URL

CVE-2021-24525

Date
Sep 20, 2021
Research Description
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2017-18580

CVE, Research URL

CVE-2017-18580

Date
Aug 22, 2019
Research Description
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2017-2245

CVE, Research URL

CVE-2017-2245

Date
Jul 07, 2017
Research Description
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2022-38086

CVE, Research URL

CVE-2022-38086

Date
Oct 12, 2022
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2023-0890

CVE, Research URL

CVE-2023-0890

Date
Mar 20, 2023
Research Description
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password protected posts. It is also possible to leak the password of protected posts
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-1808

CVE, Research URL

CVE-2024-1808

Date
Feb 28, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-2583

CVE, Research URL

CVE-2024-2583

Date
Apr 13, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2023-0911

CVE, Research URL

CVE-2023-0911

Date
Mar 20, 2023
Research Description
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2023-6225

CVE, Research URL

CVE-2023-6225

Date
Nov 28, 2023
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2023-6488

CVE, Research URL

CVE-2023-6488

Date
Dec 19, 2023
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-1510

CVE, Research URL

CVE-2024-1510

Date
Feb 20, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping on user supplied attributes and user supplied tags. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2023-23800

CVE, Research URL

CVE-2023-23800

Date
Nov 13, 2023
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-3512

CVE, Research URL

-

Date
Apr 10, 2024
Research Description
Rejected reason: **DUPLICATE*** Please use CVE-2024-2583 instead.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2023-25040

CVE, Research URL

CVE-2023-25040

Date
Mar 30, 2023
Research Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin — Shortcodes Ultimate plugin <= 5.12.6 versions.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2023-6226

CVE, Research URL

CVE-2023-6226

Date
Nov 28, 2023
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve arbitrary post meta values which may contain sensitive information when combined with another plugin.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-0792

CVE, Research URL

CVE-2024-0792

Date
Feb 29, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping on RSS feed content. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-3188

CVE, Research URL

CVE-2024-3188

Date
Apr 26, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-4542

CVE, Research URL

-

Date
May 14, 2024
Research Description
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-3548. Reason: This candidate was issued in error. Please use CVE-2024-3548 instead.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-3548

CVE, Research URL

CVE-2024-3548

Date
May 15, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-4553

CVE, Research URL

CVE-2024-4553

Date
May 21, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_members' shortcode in all versions up to, and including, 7.1.5 due to insufficient input sanitization and output escaping on user supplied 'color' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-4821

CVE, Research URL

CVE-2024-4821

Date
Jun 05, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up to, and including, 7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-3550

CVE, Research URL

CVE-2024-3550

Date
May 02, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jul 24, 2024

WP Shortcodes Plugin — Shortcodes Ultimate # PSC-2024-64510

PSC, Research URL

PSC-2024-64510

Date
-
Research Description
Shortcodes Ultimate, the leading shortcodes plugin for WordPress, has achieved the Plugin Security Certification (PSC) from CleanTalk, providing an added layer of security for its users. This comprehensive plugin offers over 50 beautiful and functional shortcodes, allowing you to enhance your WordPress site by adding useful elements in the post editor, text widgets, or even template files. With its seamless integration with the Block Editor and support for custom CSS, Shortcodes Ultimate is a versatile and powerful tool for both developers and users, now with the assurance of certified security standards.
Affected versions
Min -, max -.
Status
SAFE & CERTIFIED
Oct 23, 2024

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2024-8500

CVE, Research URL

CVE-2024-8500

Date
Oct 23, 2024
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Mar 05, 2025

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2025-0370

CVE, Research URL

CVE-2025-0370

Date
Mar 04, 2025
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jul 05, 2025

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2025-5567

CVE, Research URL

CVE-2025-5567

Date
Jul 04, 2025
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-url' DOM element attribute in all versions up to, and including, 7.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jul 21, 2025

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2025-7354

CVE, Research URL

CVE-2025-7354

Date
Jul 21, 2025
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2025-7369

CVE, Research URL

CVE-2025-7369

Date
Jul 21, 2025
Research Description
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This is due to missing or incorrect nonce validation on the preview function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. In combination with CVE-2025-7354, it leads to Reflected Cross-Site Scripting.
Affected versions
Min -, max -.
Status
vulnerable
Jul 22, 2025

WP Shortcodes Plugin — Shortcodes Ultimate # CVE-2025-8015

CVE, Research URL

CVE-2025-8015

Date
-
Research Description
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] < 7.4.3 CVE-2025-8015
Affected versions
Min -, max -.
Status
vulnerable