PT-2024-21146 · WordPress · Wp Shortcodes Plugin

Dmitry Ignatyev

·

Published

2024-03-26

·

Updated

2025-05-12

·

CVE-2024-2583

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Shortcodes Plugin versions prior to 7.0.5
Description The issue arises from the improper escaping of some shortcode attributes, which can be exploited by users with the contributor role to conduct Stored XSS attacks. This affects over 600,000 WordPress sites, potentially allowing attackers to seize control by exploiting the Stored XSS vulnerability.
Recommendations For versions prior to 7.0.5, upgrade the plugin to the latest version to mitigate the risk. As a temporary workaround, consider restricting the contributor role's access to the plugin's shortcodes until the issue is resolved. Conduct a thorough security audit to identify any potential exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2583

Affected Products

Wp Shortcodes Plugin