Vulnerabilities > Getshortcodes > Shortcodes Ultimate > 5.12.9

DATE CVE VULNERABILITY TITLE RISK
2023-12-19 CVE-2023-6488 Cross-site Scripting vulnerability in Getshortcodes Shortcodes Ultimate
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
getshortcodes CWE-79
5.4
2023-11-28 CVE-2023-6225 Cross-site Scripting vulnerability in Getshortcodes Shortcodes Ultimate
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values.
network
low complexity
getshortcodes CWE-79
5.4
2023-11-28 CVE-2023-6226 Authorization Bypass Through User-Controlled Key vulnerability in Getshortcodes Shortcodes Ultimate
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'.
network
low complexity
getshortcodes CWE-639
4.3