CVE · Medium

CVE-2022-38086 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-38086 Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 5.12.1 Cross-Site Request Forgery (CSRF) Medium 5.4 < 5.12.1 5.12.1 2022-10-02

CVE-2022-38086

The Shortcodes Ultimate plugin for WordPress versions 5.12.0 and earlier contains a Cross-Site Request Forgery vulnerability in the ajax_remove_preset() and ajax_get_preset() functions, which lack proper nonce verification. An unauthenticated attacker could modify presets by crafting a malicious request and convincing an administrator to interact with it, such as clicking a link. The vulnerability was patched in version 5.12.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.