ZeroHour

CVE-2024-2583

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p34
Published
()
Modified
Description

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.

Vendors
getshortcodes
Products
shortcodes ultimate
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.