Stored Cross-Site Scripting in Shortcodes Ultimate Plugin for WordPress
CVE-2025-0370
5.4MEDIUM
Key Information:
- Vendor
- Gn Themes
- Status
- WP Shortcodes Plugin — Shortcodes Ultimate
- Vendor
- CVE Published:
- 4 March 2025
Summary
The Shortcodes Ultimate plugin for WordPress is affected by a vulnerability that allows authenticated users with Contributor-level access or higher to exploit the ‘src’ parameter. This occurs due to inadequate input sanitization and output escaping, enabling attackers to inject and execute arbitrary web scripts on pages when accessed by users. It underscores the importance of implementing strong security measures in web applications to prevent injection attacks.
Affected Version(s)
WP Shortcodes Plugin — Shortcodes Ultimate * <= 7.3.3
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Rollings