CVE-2024-0792: WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping on RSS feed content. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0792?
CVE-2024-0792 has a high severity due to its potential to enable stored cross-site scripting attacks.
How do I fix CVE-2024-0792?
To fix CVE-2024-0792, update the WP Shortcodes Plugin — Shortcodes Ultimate to version 7.0.2 or later.
Who is affected by CVE-2024-0792?
Any WordPress site using WP Shortcodes Plugin — Shortcodes Ultimate version up to and including 7.0.1 is affected by CVE-2024-0792.
What type of vulnerability is CVE-2024-0792?
CVE-2024-0792 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
What causes CVE-2024-0792 to exist?
CVE-2024-0792 exists due to inadequate input sanitization and output escaping specifically on RSS feed content.