Getshortcodes develops a WordPress plugin ecosystem centered on its Shortcodes Ultimate product, a widely adopted tool for non-developers to add dynamic content to websites through template shortcode functionality. The vendor's vulnerability profile reflects the attack surface inherent to a user-facing content-generation plugin: recurring weakness classes cluster around improper input neutralization and cross-site scripting, cross-site request forgery, and authorization and access-control gaps, with a meaningful share reaching serious severity. These classes are characteristic of plugins that bridge admin interfaces, user input, and front-end rendering without rigorous validation boundaries. Defenders deploying this plugin should prioritize administrative access restrictions, keep the product updated, and monitor for authorization-bypass conditions that could allow unauthorized content modification or injection. Current vulnerability counts, severity distribution, and in-the-wild activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getshortcodes over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18580CRITICAL The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode. | Aug 22, 2019 | 9.8 | 44 | NO | YES |
CVE-2022-41136HIGH Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress. | Nov 8, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-0911MEDIUM The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authentica | Mar 20, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-0890MEDIUM The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be ac | Mar 20, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-25040MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin — Shortcodes Ultimate plugin <= 5.12.6 versions. | Mar 30, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-23800MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a | Nov 13, 2023 | 6.5 | 19 | NO | NO |
CVE-2021-24525MEDIUM The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its h | Sep 20, 2021 | 5.4 | 19 | NO | NO |
CVE-2025-5567MEDIUM The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-url' DOM element attribute in all versions up to, and | Jul 4, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-6766MEDIUM The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortco | Aug 6, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-4553MEDIUM The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_members' shortcode in all versions up to, and | May 21, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getshortcodes.
Media articles that mention a CVE ID that affects a product developed by Getshortcodes — matched by CVE ID, not by vendor name.