Meks Flexible Shortcodes Security & Risk Analysis

wordpress.org/plugins/meks-flexible-shortcodes

Add some cool elements to your post/page content with flexible shortcodes.

10K active installs v1.3.8 PHP + WP 3.5+ Updated Jun 10, 2025
accordionsshortcodeshortcodestabstoggles
97
A · Safe
CVEs total3
Unpatched0
Last CVEJun 12, 2025
Safety Verdict

Is Meks Flexible Shortcodes Safe to Use in 2026?

Generally Safe

Score 97/100

Meks Flexible Shortcodes has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Jun 12, 2025Updated 9mo ago
Risk Assessment

The "meks-flexible-shortcodes" plugin version 1.3.8 exhibits a mixed security posture. While the code analysis reveals good practices such as 100% of SQL queries using prepared statements and 90% of output being properly escaped, significant concerns arise from the attack surface. The presence of an AJAX handler without authentication checks is a critical vulnerability. This directly exposes a potential entry point for malicious actors to execute arbitrary actions or access sensitive information.

The vulnerability history shows a concerning pattern of 3 known medium severity Cross-Site Scripting (XSS) vulnerabilities, with the most recent one being in June 2025. Although currently unpatched vulnerabilities are zero, the repeated occurrence of XSS indicates a persistent weakness in input sanitization or output escaping for certain data flows that were not fully captured by the static analysis. The lack of nonce checks on the identified AJAX handler further exacerbates this risk, making it easier for attackers to leverage the handler without needing user interaction.

In conclusion, while the plugin demonstrates strengths in database interaction and output encoding, the unprotected AJAX handler represents a major security flaw. Coupled with the historical prevalence of XSS, this plugin requires immediate attention. The presence of a single, unprotected entry point overshadows the otherwise good coding practices, making it a significant risk for any WordPress site.

Key Concerns

  • AJAX handler without auth check
  • Missing nonce check on AJAX handler
  • 3 medium severity XSS vulnerabilities historically
Vulnerabilities
3

Meks Flexible Shortcodes Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-49855medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meks Flexible Shortcodes <= 1.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 12, 2025 Patched in 1.3.8 (6d)
CVE-2025-47621medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meks Flexible Shortcodes <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 7, 2025 Patched in 1.3.7 (7d)
CVE-2022-4562medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meks Flexible Shortcodes <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 17, 2023 Patched in 1.3.5 (645d)
Code Analysis
Analyzed Mar 16, 2026

Meks Flexible Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
54 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped60 total outputs
Attack Surface
1 unprotected

Meks Flexible Shortcodes Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_mks_generate_shortcodes_uimeks-shortcodes.php:99
WordPress Hooks 8
filterthe_contentinc\functions.php:971
actioninitmeks-shortcodes.php:17
actionadmin_initmeks-shortcodes.php:70
filtermce_buttonsmeks-shortcodes.php:76
filtermce_external_pluginsmeks-shortcodes.php:77
actionadmin_enqueue_scriptsmeks-shortcodes.php:171
actionwp_enqueue_scriptsmeks-shortcodes.php:195
actioninitmeks-shortcodes.php:220
Maintenance & Trust

Meks Flexible Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 10, 2025
PHP min version
Downloads448K

Community Trust

Rating84/100
Number of ratings10
Active installs10K
Developer Profile

Meks Flexible Shortcodes Developer Profile

Meks

14 plugins · 117K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Meks Flexible Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meks-flexible-shortcodes/css/font-awesome/css/font-awesome.min.css/wp-content/plugins/meks-flexible-shortcodes/css/simple-line/simple-line-icons.css/wp-content/plugins/meks-flexible-shortcodes/css/admin.css/wp-content/plugins/meks-flexible-shortcodes/css/style.css/wp-content/plugins/meks-flexible-shortcodes/js/admin.js/wp-content/plugins/meks-flexible-shortcodes/js/main.js
Script Paths
/wp-content/plugins/meks-flexible-shortcodes/js/admin.js/wp-content/plugins/meks-flexible-shortcodes/js/main.js
Version Parameters
/meks-flexible-shortcodes/css/font-awesome/css/font-awesome.min.css?ver=/meks-flexible-shortcodes/css/simple-line/simple-line-icons.css?ver=/meks-flexible-shortcodes/css/admin.css?ver=/meks-flexible-shortcodes/css/style.css?ver=/meks-flexible-shortcodes/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
mks_wrapmks_tabsmks_tabs_sectionshidable
Data Attributes
data-nav
JS Globals
mks_tabs_switch
Shortcode Output
[mks_col[mks_one_half[mks_one_third[mks_one_quarter
FAQ

Frequently Asked Questions about Meks Flexible Shortcodes