CVE Database /
CVE-2021-24525
CVE · Medium
CVE-2021-24525 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.10.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24525
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.10.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 5.10.2
|
5.10.2 |
2021-08-23 |
—
|
CVE-2021-24525
The Shortcodes Ultimate plugin versions prior to 5.10.2 contain a stored cross-site scripting vulnerability where contributors can inject malicious code through shortcode attributes. The plugin's attribute handling is inconsistent, with many attributes failing to properly escape user input, and certain attributes like the onclick parameter in the su_button shortcode are inherently insecure by design.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings