CVE · Medium

CVE-2021-24525 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.10.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24525 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.10.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.10.2 5.10.2 2021-08-23

CVE-2021-24525

The Shortcodes Ultimate plugin versions prior to 5.10.2 contain a stored cross-site scripting vulnerability where contributors can inject malicious code through shortcode attributes. The plugin's attribute handling is inconsistent, with many attributes failing to properly escape user input, and certain attributes like the onclick parameter in the su_button shortcode are inherently insecure by design.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.