MEDIUM (6.1)
    Plugin

    Stored Cross-Site Scripting in Shortcodes Ultimate Plugin's 'su_lightbox' Shortcode

    Published Date: 4/4/2026
    CVE ID: CVE-2026-0737

    Summary

    The Shortcodes Ultimate plugin for WordPress up to version 7.4.7 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization and escaping of the 'src' attribute in the 'su_lightbox' shortcode. Authenticated users with contributor level access or higher can exploit this to inject malicious scripts that execute when users visit the affected pages.

    Vulnerability Details

    This vulnerability arises because the 'su_lightbox' shortcode in the Shortcodes Ultimate plugin does not properly sanitize user input or escape output within the 'src' attribute. As a result, a user with contributor level access or above can introduce a script that permanently resides in the post or page content (a form of Stored XSS). When unsuspecting users visit the page containing the script, the script executes in their browser context, potentially leading to session hijacking, redirections, or other malicious activities. Since WordPress contributors typically have the permission to author content without publishing rights, this vulnerability can be exploited by contributors aiming to run malicious scripts under the assumption that their contributions will eventually be published. XSS vulnerabilities of this nature can be manipulated to steal users' credentials, manipulate page content, or perform actions on behalf of other users.

    Recommendations

    To mitigate this vulnerability, restrict contributor level access to only trusted users. Implement additional security policies that require manual review of content changes by higher-level administrators before publication. Utilize WordPress security plugins to monitor and block suspicious activities and regularly scan for vulnerabilities. Educate site users about the dangers of executing JavaScript embedded in potentially compromised sites.

    Available Fixes

    Last Updated: 4/7/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More