Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Shortcodes Ultimate < 5.10.2 - Contributor+ Stored XSS
Vulnerability Description
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
WordPress 插件 跨站脚本漏洞
Vulnerability Description
WordPress 插件是WordPress开源的一个应用插件。 WordPress 插件 Shortcodes Ultimate 5.10.2之前版本存在跨站脚本漏洞,该漏洞源于插件允许具有贡献者角色的用户通过短代码属性执行存储的XSS。
CVSS Information
N/A
Vulnerability Type
N/A