Skip to content

Known CVE

WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution

Shortcodes Ultimate plugin before 5.0.1 for WordPress contains a remote code execution caused by a filter in meta, post, or user shortcode, letting remote attackers execute arbitrary code, exploit requires sending crafted shortcode data.

CVE-2017-18580

Critical2017CVSS 8.8CWE-94

cve2017 · wordpress · wp-plugin · shortcodes-ultimate · rce · authenticated · oast · wp

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website