Show filters
141 Total Results
Displaying 131-140 of 141
Sort by:
Attacker Value
Unknown
CVE-2022-3359
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
0
Attacker Value
Unknown
CVE-2022-41136
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
0
Attacker Value
Unknown
CVE-2022-38086
Disclosure Date: October 02, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change.
0
Attacker Value
Unknown
CVE-2022-40672
Disclosure Date: September 15, 2022 (last updated February 24, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress.
0
Attacker Value
Unknown
CVE-2022-37342
Disclosure Date: September 12, 2022 (last updated February 24, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.9 at WordPress.
0
Attacker Value
Unknown
CVE-2022-1910
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-24859
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes
0
Attacker Value
Unknown
CVE-2021-24525
Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).
0
Attacker Value
Unknown
CVE-2015-9421
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
0
Attacker Value
Unknown
CVE-2017-18580
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
0