Stored Cross-Site Scripting in Shortcodes Ultimate Plugin for WordPress
CVE-2025-0370
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 March 2025
What is CVE-2025-0370?
The Shortcodes Ultimate plugin for WordPress is affected by a vulnerability that allows authenticated users with Contributor-level access or higher to exploit the ‘src’ parameter. This occurs due to inadequate input sanitization and output escaping, enabling attackers to inject and execute arbitrary web scripts on pages when accessed by users. It underscores the importance of implementing strong security measures in web applications to prevent injection attacks.
Affected Version(s)
WP Shortcodes Plugin — Shortcodes Ultimate * <= 7.3.3