The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.
We have discovered 36 live websites that are affected by CVE-2024-4217.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 36 live websites (15.25% of Shortcodes Ultimate Pro install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 13 versions ( 56.52% of all versions) |
![]() | 12 websites |
![]() | 9 websites |
![]() | 3 websites |
![]() | 2 websites |
![]() | 2 websites |
![]() | 2 websites |
![]() | 1 websites |
![]() | 1 websites |
![]() | 1 websites |
![]() | 1 websites |
.com | 10 websites |
.de | 5 websites |
.org | 5 websites |
.co.uk | 2 websites |
.ru | 2 websites |
.dk | 1 websites |
.eu | 1 websites |
.jp | 1 websites |
.net | 1 websites |
.pl | 1 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.org | ![]() | **,*** | |
******.net | ![]() | ***,*** | |
***********.pl | ![]() | *,***,*** | |
********.com | ![]() | *,***,*** | |
******************.org | ![]() | *,***,*** | |
**************.com | ![]() | *,***,*** | |
***.org | ![]() | *,***,*** | |
************.dk | ![]() | *,***,*** | |
******************.org | ![]() | *,***,*** | |
****************.de | ![]() | *,***,*** |
FAQ