PoC Index

CVE-2024-2583

MEDIUM 5.4EPSS 0.4%

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS attacks.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.40% chance of exploitation in the next 30 days, 34th percentile
Published
2024-04-13
Updated
2024-08-01

Proof-of-concept exploits (1)

References

Related