CVE-2022-41136
- EPSS 0.1%
- Veröffentlicht 08.11.2022 19:15:15
- Zuletzt bearbeitet 21.11.2024 07:22:41
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
CVE-2022-38086
- EPSS 0.11%
- Veröffentlicht 11.10.2022 20:15:15
- Zuletzt bearbeitet 21.11.2024 07:15:45
Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change.
CVE-2021-24525
- EPSS 0.18%
- Veröffentlicht 20.09.2021 10:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:14
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there...
CVE-2017-18580
- EPSS 75.16%
- Veröffentlicht 22.08.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 03:20:26
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
- EPSS 0.61%
- Veröffentlicht 07.07.2017 13:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.