CVE-2024-3188: Shortcodes Ultimate < 7.1.0 - Contributor+ Stored XSS
The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3188?
CVE-2024-3188 is classified as a moderate severity vulnerability due to its impact on user content and permissions.
How do I fix CVE-2024-3188?
To fix CVE-2024-3188, update the WP Shortcodes Plugin — Shortcodes Ultimate to version 7.1.0 or later.
Who is affected by CVE-2024-3188?
Users of the WP Shortcodes Plugin — Shortcodes Ultimate prior to version 7.1.0 are affected by CVE-2024-3188.
What type of vulnerability is CVE-2024-3188?
CVE-2024-3188 is an output validation vulnerability that allows potential script injection via shortcode attributes.
Can contributors exploit CVE-2024-3188?
Yes, users with the contributor role and above can exploit CVE-2024-3188 due to insufficient validation of shortcode attributes.