CVE · Critical

CVE-2017-18580 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.0.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-18580 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.0.1 Improper Input Validation Critical 9.8 < 5.0.1 5.0.1 2017-10-31

CVE-2017-18580

The Shortcodes Ultimate plugin before version 5.0.1 fails to properly validate the "filter" parameter in the su_meta, su_user, and su_post shortcodes, enabling attackers to assign dangerous functions like system() to execute arbitrary code on the server. This vulnerability is actively being exploited by threat actors in real-world attacks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.