CVE-2024-13362
WP Shortcodes Plugin — Shortcodes Ultimate
Minimum safe version
7.5.0
Update to 7.5.0 or later to address 40 fixable vulnerabilities
CVE-2026-3885
Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' Shortcode
Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lightbox' Shortcode
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'max_width' Shortcode Attribute
CVE-2025-12800
Shortcodes Ultimate <= 7.4.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title and Slide Link
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes
Shortcodes Ultimate <= 7.4.2 - Cross-Site Request Forgery to Arbitrary Shortcode Execution
Shortcodes Ultimate <= 7.4.0 - Authenticted (Contributor+) Stored Cross-Site Scripting via 'data-url' Attribute
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
CVE-2025-49244
WordPress Shortcodes Ultimate Plugin <= 7.3.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-8500
CVE-2024-4821
CVE-2024-4553
CVE-2024-3548
CVE-2024-4542
CVE-2024-3550
CVE-2024-3188
WordPress Shortcodes Ultimate Plugin < 7.0.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-3512
CVE-2024-1808
CVE-2024-1510
CVE-2024-0792
WordPress Shortcodes Ultimate Plugin <= 7.0.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-6225
CVE-2023-6226
WordPress Shortcodes Ultimate Plugin <= 5.13.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-0890
CVE-2023-0911
CVE-2023-25050
CVE-2023-23800
CVE-2023-25040
WordPress Shortcodes Plugin — Shortcodes Ultimate <= 4.9.3 - Cross-Site Scripting
Shortcodes Ultimate <= 5.12.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE-2022-41136
CVE-2022-38086
CVE-2017-2245
CVE-2017-18580
CVE-2021-24525