Shortcodes Ultimate < 5.10.2 - Contributor+ Stored XSS
CVE-2021-24525

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
20 September 2021

Summary

The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).

Affected Version(s)

WordPress Shortcodes Plugin — Shortcodes Ultimate 5.10.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

apple502j
.