WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Shortcodes Ultimate?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Shortcodes Ultimate — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: shortcodes-ultimate
  • 400000+ instalaciones activas

block-editorcarousellightboxshortcodeshortcodes

Estado de mantenimiento

  • Requiere PHP: 7.0+

Vulnerabilidades conocidas

38 CVEs conocidos registrados para Shortcodes Ultimate.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-13362 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.3.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 7.3.4 7.3.4 2026-04-30
CVE-2026-3885 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.5.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 7.5.0 7.5.0 2026-04-15
CVE-2025-12800 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.6 Falsificación de petición del lado del servidor (SSRF) Media 6,4 < 7.4.6 7.4.6 2025-11-23
CVE-2025-49244 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 7.4.0 7.4.0 2025-06-05
CVE-2024-8500 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.3.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.3.0 7.3.0 2024-10-22
CVE-2024-4821 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.1.7 7.1.7 2024-06-04
CVE-2024-4553 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.1.6 7.1.6 2024-05-20
CVE-2024-3548 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 7.1.2 7.1.2 2024-05-15

CVE-2024-13362

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-3885

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-12800

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via the su_shortcode_csv_table function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. If the 'Unsafe features' option is explicitly enabled by an administrator, this issue becomes exploitable by Contributor+ attackers

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-49244

The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-8500

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4821

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up to, and including, 7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4553

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_members' shortcode in all versions up to, and including, 7.1.5 due to insufficient input sanitization and output escaping on user supplied 'color' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3548

<p>WordPress Shortcodes Ultimate Plugin < 7.1.2 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Shortcodes Ultimate</p><p>Link: https://wordpress.org/plugins/shortcodes-ultimate/#developers</p><p>Affected Version < 7.1.2</p><p>Fixed in version 7.1.2 </p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

+ 33 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-3550 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.1.3 7.1.3 2024-04-29
CVE-2024-4542 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 7.1.2 7.1.2 2024-04-24
CVE-2024-3512 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 7.0.5 7.0.5 2024-04-09
CVE-2024-3188 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.1.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,3 < 7.1.0 7.1.0 2024-04-05
CVE-2024-2583 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.0.5 7.0.5 2024-03-23
CVE-2024-1808 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.0.4 7.0.4 2024-02-27
CVE-2024-1510 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.0.3 7.0.3 2024-02-19
CVE-2024-0792 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.0.2 7.0.2 2024-02-07
CVE-2023-6488 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.0.1 7.0.1 2023-12-18
CVE-2023-6226 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.0 Elusión de autorización mediante una clave controlada por el usuario Media 4,3 < 7.0.0 7.0.0 2023-11-27
CVE-2023-6225 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.0.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.0.0 7.0.0 2023-11-27
CVE-2023-33999 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.13.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 5.13.1 5.13.1 2023-07-18
CVE-2023-0911 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.8 Falta de control de autorización Media 6,5 < 5.12.8 5.12.8 2023-02-27
CVE-2023-0890 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.8 Falta de control de autorización Media 6,5 < 5.12.8 5.12.8 2023-02-27
CVE-2023-25040 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 5.12.7 5.12.7 2023-02-10
CVE-2023-23800 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7 Falsificación de petición del lado del servidor (SSRF) Alta 7,1 < 5.12.7 5.12.7 2023-02-10
CVE-2023-25050 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.7 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 7,1 < 5.12.7 5.12.7 2023-02-10
CVE-2022-41136 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 5.12.1 5.12.1 2022-10-13
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1 Desconocido < 5.12.1 5.12.1 2022-10-13
CVE-2022-38086 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 5.12.1 5.12.1 2022-10-02
CVE-2021-24525 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.10.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 5.10.2 5.10.2 2021-08-23
CVE-2017-18580 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.0.1 Validación incorrecta de la entrada Crítica 9,8 < 5.0.1 5.0.1 2017-10-31
CVE-2017-2245 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 4.10.0 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 5,0 < 4.10.0 4.10.0 2017-06-23
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 4.9.4 Desconocido < 4.9.4 4.9.4 2015-05-05
CVE-2025-0370 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.3.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.3.4 7.3.4 0000-00-00
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] <= 7.4.2 (unfixed) Media 6,4 < 7.4.2 7.4.2 0000-00-00
CVE-2025-5567 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.4.1 7.4.1 0000-00-00
CVE-2025-7369 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.3 Falsificación de petición en sitios cruzados (CSRF) Media 6,1 < 7.4.3 7.4.3 0000-00-00
CVE-2025-7354 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 7.4.3 7.4.3 0000-00-00
CVE-2025-8015 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 7.4.3 7.4.3 0000-00-00
CVE-2026-2480 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.5.0 Desconocido < 7.5.0 7.5.0 0000-00-00
CVE-2026-0737 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.8 Desconocido < 7.4.8 7.4.8 0000-00-00
CVE-2026-0738 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.9 Desconocido < 7.4.9 7.4.9 0000-00-00

CVE-2024-3550

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4542

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-3188

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_dailymotion shortcode in all versions, up to and including 7.0.5, due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-2583

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'note_color' shortcode in all versions up to, and including, 7.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-1808

Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.4). Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.0.4. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1510

Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.3). Richard Telleng (stueotue) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.0.3. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-0792

Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.2). Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.0.2. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6488

Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.1). Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.0.1. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6226

Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 7.0.0). Francesco Carlucci discovered and reported this Insecure Direct Object References (IDOR) vulnerability in WordPress Shortcodes Ultimate Plugin. An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files/folders or interact with the database. This vulnerability has been fixed in version 7.0.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6225

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-33999

Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 5.13.1). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.13.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-0911

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-0890

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password protected posts. It is also possible to leak the password of protected posts

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-25040

Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 5.12.7). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.12.7.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-23800

Update the WordPress Shortcodes Ultimate plugin to the latest available version (at least 5.12.7). Rafie Muhammad (Patchstack) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Shortcodes Ultimate Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information. This vulnerability has been fixed in version 5.12.7.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-25050

The Shortcodes Ultimate plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 5.12.6. This is due to insufficient validation on the url being supplied via the "url" attribute of the su_table shortcode. This makes it possible for authenticated attackers, with subscriber-level privileges and above, to supply paths to arbitrary files that will be returned when rendering the shortcode. This can be leveraged to read sensitive configuration files like wp-config.php. This is only exploitable when the Unsafe features option is enabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-41136

The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.12.0. This is due to missing nonce validation on the ajax_add_preset() function. This makes it possible for unauthenticated attackers to make preset changes and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1

The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘settings’ parameter saved via the ajax_add_preset() function in versions up to, and including, 5.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-38086

The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.12.0. This is due to missing or incorrect nonce validation on the ajax_remove_preset() and ajax_get_preset() functions. This makes it possible for unauthenticated attackers to make preset changes via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-24525

The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2017-18580

The Shortcodes Ultimate plugin does not sanitize the "filter" argument to the "su_meta", "su_user", and "su_post" shortcodes, allowing the filter to be set to the "system()" function which runs arbitrary code. This is being exploited in the wild; I discovered this though analysis of mod_security audit logs on two compromised sites today.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2017-2245

The WordPress plugin "Shortcodes Ultimate" contains a directory traversal vulnerability (CWE-22) in the Examples page. Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 4.9.4

The WordPress Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-0370

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Shortcodes Ultimate – Content Elements [shortcodes-ultimate] <= 7.4.2 (unfixed)

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-5567

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-url' DOM element attribute in all versions up to, and including, 7.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-7369

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This is due to missing or incorrect nonce validation on the preview function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. In combination with CVE-2025-7354, it leads to Reflected Cross-Site Scripting.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-7354

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-8015

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2480

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the `su_box` shortcode in all versions up to, and including, 7.4.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-0737

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitization and output escaping in the 'src' attribute of the su_lightbox shortcode. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-0738

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.