CVE-2024-4217
EUVD-2024-3276913.07.2024, 06:15
The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| getshortcodes | shortcodes_ultimate | 𝑥 < 7.1.5 |
𝑥
= Vulnerable software versions