The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitization and output escaping in the 'src' attribute of the su_lightbox shortcode. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 35,185 live websites that are affected by CVE-2026-0737.
| Product | |
| Category | Widgets |
| Vulnerable Domains | 35,185 live websites (61% of Shortcodes Ultimate install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 104 versions ( 97% of all versions) |
| 8,637 websites | |
| 4,759 websites | |
| 3,914 websites | |
| 3,275 websites | |
| 1,891 websites | |
| 1,136 websites | |
| 1,092 websites | |
| 994 websites | |
| 746 websites | |
| 636 websites |
| .com | 13,263 websites |
| .ru | 2,685 websites |
| .de | 2,568 websites |
| .org | 1,890 websites |
| .net | 1,187 websites |
| .jp | 1,119 websites |
| .fr | 960 websites |
| .pl | 818 websites |
| .it | 781 websites |
| .co.jp | 644 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.com | *,*** | ||
| ***.com | *,*** | ||
| ***********.net | **,*** | ||
| *************.com | **,*** | ||
| ******.com | **,*** | ||
| *********.com | **,*** | ||
| *****.org | **,*** | ||
| ******.com | **,*** | ||
| **********.com | **,*** | ||
| ******.eu | **,*** |
FAQ