CVE-2024-6766: Shortcodes Ultimate Pro < 7.2.1 - Contributor+ Stored XSS
The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6766?
CVE-2024-6766 is classified as a medium severity vulnerability due to the potential for Stored Cross-Site Scripting.
How do I fix CVE-2024-6766?
Updating the Shortcodes Ultimate Pro WordPress plugin to version 7.2.1 or later will remediate CVE-2024-6766.
Who is affected by CVE-2024-6766?
CVE-2024-6766 affects users of the Shortcodes Ultimate Pro WordPress plugin versions prior to 7.2.1.
What type of attack can CVE-2024-6766 facilitate?
CVE-2024-6766 can facilitate Stored Cross-Site Scripting attacks, allowing malicious scripts to be stored and executed.
What versions of Shortcodes Ultimate Pro are vulnerable to CVE-2024-6766?
Versions of the Shortcodes Ultimate Pro plugin before 7.2.1 are vulnerable to CVE-2024-6766.