CVE-2024-4217

Shortcodes Ultimate Pro < 7.1.5 - Contributor+ Stored Cross-Site Scripting XSS

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.


We have discovered 36 live websites that are affected by CVE-2024-4217.

Test my site




Affected Software

Product  Shortcodes Ultimate Pro
Category Wordpress Plugins
Vulnerable Domains36 live websites (15.25% of Shortcodes Ultimate Pro install base)
Vulnerable Versions
  • from 0 before 7.1.5
Vulnerable Versions Count13 versions ( 56.52% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 13, 2024
  • Updated - Aug 1, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-4217 usage by Country

United States12 websites



Germany9 websites
Japan3 websites
GB2 websites
Mexico2 websites
Russia2 websites
Austria1 websites
Bulgaria1 websites
Canada1 websites
Denmark1 websites

CVE-2024-4217 usage by TLD

.com10 websites
.de5 websites
.org5 websites
.co.uk2 websites
.ru2 websites
.dk1 websites
.eu1 websites
.jp1 websites
.net1 websites
.pl1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4217

Top websites that are affected by CVE-2024-4217. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.org United States**,***
******.net United States***,***
***********.pl Poland*,***,***
********.com Germany*,***,***
******************.org United States*,***,***
**************.com United States*,***,***
***.org United States*,***,***
************.dk Denmark*,***,***
******************.org United States*,***,***
****************.de Germany*,***,***
See full domain list

FAQ

CVE-2024-4217 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Shortcodes Ultimate Pro
A total of 36 websites have been identified as vulnerable to CVE-2024-4217, discovered through global website indexing conducted by WebTechSurvey.
Shortcodes Ultimate Pro is susceptible to CVE-2024-4217 vulnerability.
Shortcodes Ultimate Pro versions before 7.1.5 are vulnerable to CVE-2024-4217.
Version 7.1.5 of Shortcodes Ultimate Pro addresses the CVE-2024-4217 security vulnerability.