CVE-2024-8500: WP Shortcodes Plugin — Shortcodes Ultimate <= 7.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8500?
CVE-2024-8500 is rated as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-8500?
To fix CVE-2024-8500, upgrade the WP Shortcodes Plugin — Shortcodes Ultimate to version 7.3.0 or later.
Which versions of Shortcodes Ultimate are affected by CVE-2024-8500?
CVE-2024-8500 affects all versions of the Shortcodes Ultimate plugin up to and including version 7.2.2.
What type of vulnerability is CVE-2024-8500?
CVE-2024-8500 is a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization.
Who is impacted by CVE-2024-8500?
Users of the Shortcodes Ultimate plugin for WordPress, specifically those using versions up to 7.2.2, are impacted by CVE-2024-8500.