cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forthemify-shortcodes themify-shortcodes

Direction: descending
Apr 18, 2025

Themify Shortcodes # CVE-2025-39581

CVE, Research URL

CVE-2025-39581

Application

Themify Shortcodes

Date
Apr 16, 2025
Research Description
Themify Shortcodes [themify-shortcodes] < 2.1.4 CVE-2025-39581 [en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Shortcodes allows Stored XSS. This issue affects Themify Shortcodes: from n/a through 2.1.3.
Affected versions
Min -, max -.
Status
vulnerable
Aug 12, 2024

Themify Shortcodes # CVE-2024-43133

CVE, Research URL

CVE-2024-43133

Application

Themify Shortcodes

Date
-
Research Description
Themify Shortcodes [themify-shortcodes] < 2.1.2 CVE-2024-43133
Affected versions
Min -, max -.
Status
vulnerable
Jun 07, 2024

Themify Shortcodes # CVE-2022-4787

CVE, Research URL

CVE-2022-4787

Application

Themify Shortcodes

Date
Jan 31, 2023
Research Description
Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Affected versions
Min -, max -.
Status
vulnerable

Themify Shortcodes # CVE-2024-4567

CVE, Research URL

CVE-2024-4567

Application

Themify Shortcodes

Date
May 14, 2024
Research Description
The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Themify Shortcodes # CVE-2024-2732

CVE, Research URL

CVE-2024-2732

Application

Themify Shortcodes

Date
Mar 26, 2024
Research Description
The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable