Show filters
141 Total Results
Displaying 111-120 of 141
Sort by:
Attacker Value
Unknown
CVE-2023-44994
Disclosure Date: October 10, 2023 (last updated October 13, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.
0
Attacker Value
Unknown
CVE-2023-44475
Disclosure Date: October 10, 2023 (last updated October 13, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions.
0
Attacker Value
Unknown
CVE-2023-41728
Disclosure Date: October 02, 2023 (last updated April 29, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a through 2.5.
0
Attacker Value
Unknown
CVE-2023-1273
Disclosure Date: July 04, 2023 (last updated October 08, 2023)
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
0
Attacker Value
Unknown
CVE-2022-4623
Disclosure Date: July 04, 2023 (last updated October 08, 2023)
The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2022-4950
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
0
Attacker Value
Unknown
CVE-2023-23703
Disclosure Date: May 16, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Arconix Shortcodes plugin <= 2.1.7 versions.
0
Attacker Value
Unknown
CVE-2023-25798
Disclosure Date: May 03, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <= 1.1.9 versions.
0
Attacker Value
Unknown
CVE-2023-25040
Disclosure Date: March 30, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin — Shortcodes Ultimate plugin <= 5.12.6 versions.
0
Attacker Value
Unknown
CVE-2023-0911
Disclosure Date: March 20, 2023 (last updated February 24, 2025)
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.
0