Show filters
141 Total Results
Displaying 101-110 of 141
Sort by:
Attacker Value
Unknown
CVE-2023-47815
Disclosure Date: November 22, 2023 (last updated November 29, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra plugin <= 2.5.2 versions.
0
Attacker Value
Unknown
CVE-2023-5704
Disclosure Date: November 22, 2023 (last updated November 29, 2023)
The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-5338
Disclosure Date: November 22, 2023 (last updated November 28, 2023)
The Theme Blvd Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-47695
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Shortcodes Finder plugin <= 1.5.3 versions.
0
Attacker Value
Unknown
CVE-2023-23800
Disclosure Date: November 13, 2023 (last updated November 18, 2023)
Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.
0
Attacker Value
Unknown
CVE-2023-47231
Disclosure Date: November 08, 2023 (last updated November 16, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.
0
Attacker Value
Unknown
CVE-2023-5237
Disclosure Date: October 31, 2023 (last updated November 09, 2023)
The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.
0
Attacker Value
Unknown
CVE-2023-5566
Disclosure Date: October 30, 2023 (last updated November 04, 2023)
The Simple Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-46072
Disclosure Date: October 26, 2023 (last updated November 07, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions.
0
Attacker Value
Unknown
CVE-2023-4783
Disclosure Date: October 16, 2023 (last updated October 20, 2023)
The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0