CVE Database /
CVE-2017-18580
CVE · Critical
CVE-2017-18580 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.0.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-18580
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.0.1 |
Improper Input Validation |
Critical
9.8
|
< 5.0.1
|
5.0.1 |
2017-10-31 |
—
|
CVE-2017-18580
The Shortcodes Ultimate plugin before version 5.0.1 fails to properly validate the "filter" parameter in the su_meta, su_user, and su_post shortcodes, enabling attackers to assign dangerous functions like system() to execute arbitrary code on the server. This vulnerability is actively being exploited by threat actors in real-world attacks.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings