Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
References
Link | Resource |
---|---|
https://patchstack.com/database/vulnerability/shortcodes-ultimate/wordpress-shortcodes-ultimate-plugin-5-12-0-csrf-vulnerability-leading-to-stored-xss?_s_id=cve | Third Party Advisory |
https://wordpress.org/plugins/shortcodes-ultimate/#developers | Product Release Notes Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Patchstack
Published: 2022-10-12T00:00:00
Updated: 2022-11-08T00:00:00
Reserved: 2022-09-27T00:00:00
Link: CVE-2022-41136
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-11-08T19:15:15.500
Modified: 2022-11-09T13:48:33.217
Link: CVE-2022-41136
JSON object: View
Redhat Information
No data.