← Vulnerability feed

Vulnerability record · CVE-2017-18580 · published 22 August 2019

CVE-2017-18580: Getshortcodes shortcodes ultimate improper input validation vulnerability

Getshortcodes · Shortcodes Ultimate

The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.

9.8 CVSS 3.0 Critical EPSS 12% · top 4.0% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 7.5
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-18580 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-41136Getshortcodes shortcodes ultimate cross-site scripting vulnerabilityCross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12…EPSS 0.33%6.5CVE-2023-23800Getshortcodes shortcodes ultimate server-side request forgery (ssrf) vulnerabilityServer-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin —…EPSS 0.49%6.5CVE-2023-0890Getshortcodes shortcodes ultimate missing authorization vulnerabilityThe WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes a…EPSS 0.65%6.5CVE-2023-0911Getshortcodes shortcodes ultimate missing authorization vulnerabilityThe WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user sho…EPSS 0.65%6.3CVE-2024-3188Getshortcodes shortcodes ultimate cross-site scripting vulnerabilityThe WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before out…EPSS 0.44%6.1CVE-2024-3548Getshortcodes shortcodes ultimate cross-site scripting vulnerabilityThe WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in th…EPSS 0.44%5.4CVE-2025-5567Getshortcodes shortcodes ultimate cross-site scripting vulnerabilityThe WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-url' DOM element attri…EPSS 0.19%5.4CVE-2024-8500Getshortcodes shortcodes ultimate cross-site scripting vulnerabilityThe WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all ve…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2017-18580), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.