CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-0792

Medium Severity
Getshortcodes
SVRS
30/100

CVSSv3
5.4/10

EPSS
0.00136/1

CVE-2024-0792 is a Stored Cross-Site Scripting (XSS) vulnerability found in the WP Shortcodes Plugin – Shortcodes Ultimate plugin for WordPress. This flaw, affecting versions up to 7.0.1, allows attackers with contributor-level permissions or higher to inject malicious web scripts into pages via shortcodes, compromising the security of the WordPress site. Although the CVSS score is 5.4, indicating a medium severity, the low SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests it is not currently a critical threat. The lack of immediate concern is based on the limited presence of threat actor activity in the dark web and social media. However, successful exploitation could lead to unauthorized access, data theft, or website defacement. Regular monitoring for changes in the SVRS score remains essential for maintaining website security and addressing potential risks. Update the plugin to a patched version to mitigate this vulnerability.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:L
UI:R
S:C
C:L
I:L
A:N
2024-02-29

2025-01-27

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-0792 | WP Shortcodes Plugin up to 7.0.1 on WordPress Shortcode cross site scripting (ID 3026377)
vuldb.com2025-01-27
CVE-2024-0792 | WP Shortcodes Plugin up to 7.0.1 on WordPress Shortcode cross site scripting (ID 3026377) | A vulnerability classified as problematic has been found in WP Shortcodes Plugin up to 7.0.1 on WordPress. Affected is an unknown function of the component Shortcode Handler. The manipulation leads to cross site scripting. This vulnerability is traded as CVE-2024-0792. It is possible to launch
cve-2024-0792
wordpress
possible
unknown

Social Media

No tweets found for this CVE

Affected Software

Configuration 1
TypeVendorProduct
AppGetshortcodesshortcodes_ultimate

References

ReferenceLink
[email protected]https://plugins.trac.wordpress.org/browser/shortcodes-ultimate/trunk/includes/shortcodes/feed.php#L49
[email protected]https://plugins.trac.wordpress.org/browser/shortcodes-ultimate/trunk/includes/shortcodes/feed.php#L78
[email protected]https://plugins.trac.wordpress.org/changeset/3026377/
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/0d8c043c-e347-4dc8-8a72-943a7e6c4394?source=cve
AF854A3A-2127-422B-91AE-364DA2661108https://plugins.trac.wordpress.org/browser/shortcodes-ultimate/trunk/includes/shortcodes/feed.php#L49
AF854A3A-2127-422B-91AE-364DA2661108https://plugins.trac.wordpress.org/browser/shortcodes-ultimate/trunk/includes/shortcodes/feed.php#L78
AF854A3A-2127-422B-91AE-364DA2661108https://plugins.trac.wordpress.org/changeset/3026377/
AF854A3A-2127-422B-91AE-364DA2661108https://www.wordfence.com/threat-intel/vulnerabilities/id/0d8c043c-e347-4dc8-8a72-943a7e6c4394?source=cve
[email protected]https://plugins.trac.wordpress.org/browser/shortcodes-ultimate/trunk/includes/shortcodes/feed.php#L49
[email protected]https://plugins.trac.wordpress.org/browser/shortcodes-ultimate/trunk/includes/shortcodes/feed.php#L78
[email protected]https://plugins.trac.wordpress.org/changeset/3026377/
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/0d8c043c-e347-4dc8-8a72-943a7e6c4394?source=cve

CWE Details

CWE IDCWE NameDescription
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence