CVE-2024-2583: Shortcodes Ultimate < 7.0.5 - Contributor+ Stored XSS
The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2583?
CVE-2024-2583 has a medium severity rating due to its potential for Stored XSS attacks impacting users.
How do I fix CVE-2024-2583?
To fix CVE-2024-2583, update the WP Shortcodes Plugin to version 7.0.5 or later.
Who is affected by CVE-2024-2583?
Users with the contributor role can exploit CVE-2024-2583 to conduct Stored XSS attacks.
What is the impact of CVE-2024-2583?
CVE-2024-2583 allows for Stored XSS, which can lead to unauthorized script execution in the context of a user's session.
Is there a workaround for CVE-2024-2583?
Currently, the best course of action is to update to the latest version, as there is no specific workaround for CVE-2024-2583.