Vulnerability Description
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getshortcodes | Shortcodes Ultimate | < 5.10.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/7f5659bd-50c3-4725-95f4-cf88812acf1cExploitThird Party Advisory
- https://wpscan.com/vulnerability/7f5659bd-50c3-4725-95f4-cf88812acf1cExploitThird Party Advisory
FAQ
What is CVE-2021-24525?
CVE-2021-24525 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode...
How severe is CVE-2021-24525?
CVE-2021-24525 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24525?
Check the references section above for vendor advisories and patch information. Affected products include: Getshortcodes Shortcodes Ultimate.