CVE-2024-0792
Getshortcodes
CVE-2024-0792 is a Stored Cross-Site Scripting (XSS) vulnerability found in the WP Shortcodes Plugin – Shortcodes Ultimate plugin for WordPress. This flaw, affecting versions up to 7.0.1, allows attackers with contributor-level permissions or higher to inject malicious web scripts into pages via shortcodes, compromising the security of the WordPress site. Although the CVSS score is 5.4, indicating a medium severity, the low SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests it is not currently a critical threat. The lack of immediate concern is based on the limited presence of threat actor activity in the dark web and social media. However, successful exploitation could lead to unauthorized access, data theft, or website defacement. Regular monitoring for changes in the SVRS score remains essential for maintaining website security and addressing potential risks. Update the plugin to a patched version to mitigate this vulnerability.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.