+ 33 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-3550
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.1.3
|
7.1.3 |
2024-04-29 |
—
|
|
CVE-2024-4542
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Desconocido
|
< 7.1.2
|
7.1.2 |
2024-04-24 |
—
|
|
CVE-2024-3512
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Desconocido
|
< 7.0.5
|
7.0.5 |
2024-04-09 |
—
|
|
CVE-2024-3188
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,3
|
< 7.1.0
|
7.1.0 |
2024-04-05 |
—
|
|
CVE-2024-2583
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.0.5
|
7.0.5 |
2024-03-23 |
—
|
|
CVE-2024-1808
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.0.4
|
7.0.4 |
2024-02-27 |
—
|
|
CVE-2024-1510
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.0.3
|
7.0.3 |
2024-02-19 |
—
|
|
CVE-2024-0792
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.0.2
|
7.0.2 |
2024-02-07 |
—
|
|
CVE-2023-6488
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.0.1
|
7.0.1 |
2023-12-18 |
—
|
|
CVE-2023-6226
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.0 |
Elusión de autorización mediante una clave controlada por el usuario |
Media
4,3
|
< 7.0.0
|
7.0.0 |
2023-11-27 |
—
|
|
CVE-2023-6225
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.0.0
|
7.0.0 |
2023-11-27 |
—
|
|
CVE-2023-33999
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.13.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 5.13.1
|
5.13.1 |
2023-07-18 |
—
|
|
CVE-2023-0911
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.8 |
Falta de control de autorización |
Media
6,5
|
< 5.12.8
|
5.12.8 |
2023-02-27 |
—
|
|
CVE-2023-0890
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.8 |
Falta de control de autorización |
Media
6,5
|
< 5.12.8
|
5.12.8 |
2023-02-27 |
—
|
|
CVE-2023-25040
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 5.12.7
|
5.12.7 |
2023-02-10 |
—
|
|
CVE-2023-23800
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7 |
Falsificación de petición del lado del servidor (SSRF) |
Alta
7,1
|
< 5.12.7
|
5.12.7 |
2023-02-10 |
—
|
|
CVE-2023-25050
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Alta
7,1
|
< 5.12.7
|
5.12.7 |
2023-02-10 |
—
|
|
CVE-2022-41136
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 5.12.1
|
5.12.1 |
2022-10-13 |
—
|
|
—
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1 |
— |
Desconocido
|
< 5.12.1
|
5.12.1 |
2022-10-13 |
—
|
|
CVE-2022-38086
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
5,4
|
< 5.12.1
|
5.12.1 |
2022-10-02 |
—
|
|
CVE-2021-24525
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.10.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 5.10.2
|
5.10.2 |
2021-08-23 |
—
|
|
CVE-2017-18580
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.0.1 |
Validación incorrecta de la entrada |
Crítica
9,8
|
< 5.0.1
|
5.0.1 |
2017-10-31 |
—
|
|
CVE-2017-2245
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 4.10.0 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Media
5,0
|
< 4.10.0
|
4.10.0 |
2017-06-23 |
—
|
|
—
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 4.9.4 |
— |
Desconocido
|
< 4.9.4
|
4.9.4 |
2015-05-05 |
—
|
|
CVE-2025-0370
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.3.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.3.4
|
7.3.4 |
0000-00-00 |
—
|
|
—
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] <= 7.4.2 (unfixed) |
— |
Media
6,4
|
< 7.4.2
|
7.4.2 |
0000-00-00 |
—
|
|
CVE-2025-5567
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 7.4.1
|
7.4.1 |
0000-00-00 |
—
|
|
CVE-2025-7369
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.3 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
6,1
|
< 7.4.3
|
7.4.3 |
0000-00-00 |
—
|
|
CVE-2025-7354
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 7.4.3
|
7.4.3 |
0000-00-00 |
—
|
|
CVE-2025-8015
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 7.4.3
|
7.4.3 |
0000-00-00 |
—
|
|
CVE-2026-2480
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.5.0 |
— |
Desconocido
|
< 7.5.0
|
7.5.0 |
0000-00-00 |
—
|
|
CVE-2026-0737
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.8 |
— |
Desconocido
|
< 7.4.8
|
7.4.8 |
0000-00-00 |
—
|
|
CVE-2026-0738
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.9 |
— |
Desconocido
|
< 7.4.9
|
7.4.9 |
0000-00-00 |
—
|
CVE-2024-3550
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-4542
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-3188
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_dailymotion shortcode in all versions, up to and including 7.0.5, due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-2583
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'note_color' shortcode in all versions up to, and including, 7.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-1808
Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.4).
Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.0.4.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1510
Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.3).
Richard Telleng (stueotue) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.0.3.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-0792
Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.2).
Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.0.2.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-6488
Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.1).
Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.0.1.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-6226
Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.0).
Francesco Carlucci discovered and reported this Insecure Direct Object References (IDOR) vulnerability in WordPress Shortcodes Ultimate Plugin. An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files/folders or interact with the database. This vulnerability has been fixed in version 7.0.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-6225
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-33999
Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 5.13.1).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.13.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-0911
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0890
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password protected posts. It is also possible to leak the password of protected posts
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-25040
Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 5.12.7).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.12.7.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-23800
Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 5.12.7).
Rafie Muhammad (Patchstack) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information. This vulnerability has been fixed in version 5.12.7.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-25050
The Shortcodes Ultimate plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 5.12.6. This is due to insufficient validation on the url being supplied via the "url" attribute of the su_table shortcode. This makes it possible for authenticated attackers, with subscriber-level privileges and above, to supply paths to arbitrary files that will be returned when rendering the shortcode. This can be leveraged to read sensitive configuration files like wp-config.php. This is only exploitable when the Unsafe features option is enabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-41136
The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.12.0. This is due to missing nonce validation on the ajax_add_preset() function. This makes it possible for unauthenticated attackers to make preset changes and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1
The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘settings’ parameter saved via the ajax_add_preset() function in versions up to, and including, 5.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-38086
The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.12.0. This is due to missing or incorrect nonce validation on the ajax_remove_preset() and ajax_get_preset() functions. This makes it possible for unauthenticated attackers to make preset changes via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-24525
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2017-18580
The Shortcodes Ultimate plugin does not sanitize the "filter" argument to the "su_meta", "su_user", and "su_post" shortcodes, allowing the filter to be set to the "system()" function which runs arbitrary code.
This is being exploited in the wild; I discovered this though analysis of mod_security audit logs on two compromised sites today.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2017-2245
The WordPress plugin "Shortcodes Ultimate" contains a directory traversal vulnerability (CWE-22) in the Examples page. Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 4.9.4
The WordPress Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-0370
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] <= 7.4.2 (unfixed)
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-5567
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-url' DOM element attribute in all versions up to, and including, 7.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-7369
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This is due to missing or incorrect nonce validation on the preview function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.
In combination with CVE-2025-7354, it leads to Reflected Cross-Site Scripting.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-7354
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-8015
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2480
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the `su_box` shortcode in all versions up to, and including, 7.4.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-0737
The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitization and output escaping in the 'src' attribute of the su_lightbox shortcode. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-0738
The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.