| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-10342 | League of Legends Shortcodes <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | tezzeract | League of Legends Shortcodes | Medium | 6.4 | 2024-10-25 07:37:58 | Deep Dive |
| CVE-2024-8500 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 5.4 | 2024-10-23 11:04:27 | Deep Dive |
| CVE-2024-9703 | Arconix Shortcodes <= 2.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | tychesoftwares | Arconix Shortcodes | Medium | 6.4 | 2024-10-18 06:51:27 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-9696 | Rescue Shortcodes <= 2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | rescuethemes | Rescue Shortcodes | Medium | 6.4 | 2024-10-12 08:41:06 | Deep Dive |
| CVE-2024-9581 | Shortcodes AnyWhere <= 1.0.1 - Unauthenticated Arbitrary Shortcode Execution | happyplugins | Shortcodes AnyWhere | High | 7.3 | 2024-10-10 02:06:09 | Deep Dive |
| CVE-2024-8486 | Shortcodes and extra features for Phlox theme <= 2.16.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-10-05 07:39:01 | Deep Dive |
| CVE-2024-9027 | WPZOOM Shortcodes <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via box Shortcode | wpzoom | WPZOOM Shortcodes | Medium | 6.4 | 2024-09-25 02:05:04 | Deep Dive |
| CVE-2024-43133 | WordPress Themify Shortcodes plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability | Themify | Themify Shortcodes | Medium | 6.5 | 2024-08-12 22:28:09 | Deep Dive |
| CVE-2024-6766 | Shortcodes Ultimate Pro < 7.2.1 - Contributor+ Stored XSS | Unknown | shortcodes-ultimate-pro | - | - | 2024-08-06 06:00:07 | Deep Dive |
| CVE-2024-37097 | WordPress Shortcodes by United Themes plugin < 5.0.5 - Reflected Cross Site Scripting (XSS) vulnerability | UnitedThemes | Shortcodes by United Themes | High | 7.1 | 2024-07-22 10:00:41 | Deep Dive |
| CVE-2024-4217 | Shortcodes Ultimate Pro < 7.1.5 - Contributor+ Stored Cross-Site Scripting XSS | Unknown | shortcodes-ultimate-pro | - | - | 2024-07-13 06:00:06 | Deep Dive |
| CVE-2023-7062 | Advanced File Manager Shortcodes <= 2.4 - Authenticated (Contributor+) Directory Traversal | Advanced File Manager | Advanced File Manager Shortcodes | High | 8.8 | 2024-07-10 02:02:47 | Deep Dive |
| CVE-2023-7061 | Advanced File Manager Shortcode <= 2.5.3 - Authenticated (Contributor+) Arbitrary File Upload | Advanced File Manager | Advanced File Manager Shortcodes | High | 8.8 | 2024-07-10 02:02:41 | Deep Dive |
| CVE-2024-5946 | Squelch Tabs and Accordions Shortcodes <= 0.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via tab Shortcode | squelch | Squelch Tabs and Accordions Shortcodes | Medium | 6.4 | 2024-07-09 11:02:41 | Deep Dive |
| CVE-2024-4543 | Snippet Shortcodes <= 4.1.4 - Cross-Site Request Forgery | aliakro | Snippet Shortcodes | Medium | 4.3 | 2024-07-03 04:31:32 | Deep Dive |
| CVE-2024-4377 | DOP Shortcodes <= 1.2 - Contributor+ Stored XSS via Shortcode | Unknown | DOP Shortcodes | 中危 | - | 2024-06-21 06:00:03 | Deep Dive |
| CVE-2024-34763 | WordPress Builder for WooCommerce reviews shortcodes – ReviewShort plugin <= 1.01.5 - Broken Access Control vulnerability | Saleswonder Team: Tobias | Builder for WooCommerce reviews shortcodes – ReviewShort | Medium | 5.3 | 2024-06-11 16:57:38 | Deep Dive |
| CVE-2024-4821 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_lightbox Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2024-06-05 08:33:17 | Deep Dive |
| CVE-2024-5220 | ND Shortcodes <= 7.5 - Authenticated (Author+) Stored Cross-Site Scripting | nicdark | ND Shortcodes | Medium | 6.4 | 2024-05-25 01:51:00 | Deep Dive |