| CVE-2024-4553 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_members Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2024-05-21 09:31:51 | Deep Dive |
| CVE-2024-3810 | Salient Shortcodes <= 1.5.3 - Authenticated (Contributor+) Local File Inclusion via Shortcode | ThemeNectar | Salient Shortcodes | High | 8.8 | 2024-05-18 05:40:03 | Deep Dive |
| CVE-2024-3811 | Salient Shortcodes <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | ThemeNectar | Salient Shortcodes | Medium | 6.4 | 2024-05-18 05:40:02 | Deep Dive |
| CVE-2023-37888 | WordPress Phlox Core Elements plugin <= 2.14.0 - Unauthenticated Local File Inclusion vulnerability | By Averta | Shortcodes and extra features for Phlox theme | High | 7.6 | 2024-05-17 06:48:41 | Deep Dive |
| CVE-2023-25050 | WordPress Shortcodes Ultimate plugin <= 5.12.6 - Arbitrary File Download vulnerability | Vova Anokhin | Shortcodes Ultimate | High | 7.1 | 2024-05-17 06:34:45 | Deep Dive |
| CVE-2024-3548 | Shortcodes Ultimate < 7.1.2 - Contributor+ Stored XSS | Unknown | WP Shortcodes Plugin — Shortcodes Ultimate | - | - | 2024-05-15 06:00:03 | Deep Dive |
| CVE-2024-4463 | Squelch Tabs and Accordions Shortcodes <= 0.4.7 - Cross-Site Request Forgery | squelch | Squelch Tabs and Accordions Shortcodes | Medium | 4.3 | 2024-05-09 20:03:39 | Deep Dive |
| CVE-2024-4567 | Themify Shortcodes <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcode | themifyme | Themify Shortcodes | Medium | 6.4 | 2024-05-09 20:03:38 | Deep Dive |
| CVE-2024-4233 | Broken Access Control vulnerability in multiple WordPress plugins by Tyche Softwares | Tyche Softwares | Print Invoice & Delivery Notes for WooCommerce | Medium | 4.3 | 2024-05-08 13:20:00 | Deep Dive |
| CVE-2023-7064 | Shortcodes and extra features for Phlox theme <= 2.17.5 - Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer | averta | Shortcodes and extra features for Phlox theme | High | 7.5 | 2024-05-02 16:52:51 | Deep Dive |
| CVE-2024-3550 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2024-05-02 16:52:33 | Deep Dive |
| CVE-2024-3517 | Shortcodes and extra features for Phlox theme <= 2.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Widget | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-05-02 16:52:29 | Deep Dive |
| CVE-2024-1533 | Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-05-02 16:52:23 | Deep Dive |
| CVE-2024-1396 | Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-05-02 16:52:08 | Deep Dive |
| CVE-2024-3341 | Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_gmaps' Shortcode | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-05-02 16:51:59 | Deep Dive |
| CVE-2024-1348 | Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-05-02 16:51:45 | Deep Dive |
| CVE-2024-3188 | Shortcodes Ultimate < 7.1.0 - Contributor+ Stored XSS | Unknown | WP Shortcodes Plugin — Shortcodes Ultimate | - | - | 2024-04-26 05:00:05 | Deep Dive |
| CVE-2024-1357 | Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_timeline' Shortcode | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-04-16 09:33:00 | Deep Dive |
| CVE-2024-2583 | Shortcodes Ultimate < 7.0.5 - Contributor+ Stored XSS | Unknown | WP Shortcodes Plugin — Shortcodes Ultimate | 中危 | - | 2024-04-13 05:00:02 | Deep Dive |
| CVE-2024-2499 | Squelch Tabs and Accordions Shortcodes <= 0.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via accordions Shortcode | squelch | Squelch Tabs and Accordions Shortcodes | Medium | 6.4 | 2024-04-05 12:52:40 | Deep Dive |