The Shortcodes Ultimate plugin for WordPress up to version 7.4.7 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization and escaping of the 'src' attribute in the 'su_lightbox' shortcode. Authenticated users with contributor level access or higher can exploit this to inject malicious scripts that execute when users visit the affected pages.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.