PT-2024-21146 · WordPress · Wp Shortcodes Plugin
Dmitry Ignatyev
·
Published
2024-03-26
·
Updated
2025-05-12
·
CVE-2024-2583
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Shortcodes Plugin versions prior to 7.0.5
Description
The issue arises from the improper escaping of some shortcode attributes, which can be exploited by users with the contributor role to conduct Stored XSS attacks. This affects over 600,000 WordPress sites, potentially allowing attackers to seize control by exploiting the Stored XSS vulnerability.
Recommendations
For versions prior to 7.0.5, upgrade the plugin to the latest version to mitigate the risk. As a temporary workaround, consider restricting the contributor role's access to the plugin's shortcodes until the issue is resolved. Conduct a thorough security audit to identify any potential exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Shortcodes Plugin