
WP Shortcodes Plugin — Shortcodes Ultimate Security & Risk Analysis
wordpress.org/plugins/shortcodes-ultimateA comprehensive collection of visual components for your site
Is WP Shortcodes Plugin — Shortcodes Ultimate Safe to Use in 2026?
Generally Safe
Score 88/100WP Shortcodes Plugin — Shortcodes Ultimate has a strong security track record. Known vulnerabilities have been patched promptly.
The Shortcodes Ultimate plugin version 7.4.9 exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries with 100% prepared statements and a high rate of output escaping (93%), significant concerns arise from its attack surface. The presence of 8 AJAX handlers, with 4 of them lacking authentication checks, presents a substantial risk of unauthorized actions. This is further amplified by taint analysis revealing one high severity flow with unsanitized paths, indicating a potential for attackers to exploit these entry points. The plugin's historical vulnerability record is a major red flag, with 32 known CVEs, predominantly in medium and high severity categories, including critical types like SSRF, XSS, and Path Traversal. Although there are currently no unpatched vulnerabilities, the sheer volume and nature of past issues suggest a recurring pattern of security weaknesses that require diligent attention. The plugin's strengths lie in its secure data handling for SQL and output, but the exposed entry points and past vulnerability trends necessitate caution.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow (unsanitized path)
- Numerous past high/medium severity CVEs
- Bundled Freemius v1.0 library
WP Shortcodes Plugin — Shortcodes Ultimate Security Vulnerabilities
CVEs by Year
Severity Breakdown
32 total CVEs
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.5 - Authenticated (Administrator+) Server-Side Request Forgery
Shortcodes Ultimate <= 7.4.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title and Slide Link
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes
Shortcodes Ultimate <= 7.4.2 - Cross-Site Request Forgery to Arbitrary Shortcode Execution
Shortcodes Ultimate <= 7.4.0 - Authenticted (Contributor+) Stored Cross-Site Scripting via 'data-url' Attribute
Shortcodes Ultimate <= 7.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via src Parameter
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_lightbox Shortcode
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_members Shortcode
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_lightbox
Shortcodes Ultimate <= 7.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Shortcodes Ultimate <= 7.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_color' Shortcode
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_qrcode Shortcode
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_tooltip Shortcode
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Shortcodes Plugin — Shortcodes Ultimate <= 5.13.3 - Insecure Direct Object Reference to Information Disclosure
WP Shortcodes Plugin — Shortcodes Ultimate <= 5.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Shortcodes Ultimate <= 5.12.7 - Authenticated (Subscriber+) Information Exposure
Shortcodes Ultimate <= 5.12.7 - Authenticated (Subscriber+) Arbitrary Post Access via Shortcode
Shortcodes Ultimate <= 5.12.6 - Authenticated (Subscriber+) Arbitrary File Read via Shortcode
Shortcodes Ultimate <= 5.12.6 - Authenticated (Subscriber+) Server-Side Request Forgery
Shortcodes Ultimate <= 5.12.6 - Authenticated (Contributor+) Stored Cross Site Scripting
Shortcodes Ultimate <= 5.12.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Shortcodes Ultimate <= 5.12.0 - Cross-Site Request Forgery
Shortcodes Ultimate <= 5.12.0 - Cross-Site Request Forgery
WordPress Shortcodes Plugin — Shortcodes Ultimate <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Shortcodes Plugin — Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution
WordPress Shortcodes Plugin — Shortcodes Ultimate < 4.10.0 - Directory Traversal
WordPress Shortcodes Plugin — Shortcodes Ultimate <= 4.9.3 - Cross-Site Scripting
WP Shortcodes Plugin — Shortcodes Ultimate Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Shortcodes Plugin — Shortcodes Ultimate Attack Surface
AJAX Handlers 8
WordPress Hooks 46
Maintenance & Trust
WP Shortcodes Plugin — Shortcodes Ultimate Maintenance & Trust
Maintenance Signals
Community Trust
WP Shortcodes Plugin — Shortcodes Ultimate Alternatives
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Mimo Carousel
mimo-carousel
Create Custom Carousels with no code knowledge. Choose Columns, show/hide arrows/dots and a lot of options, display any taxonomy.
Latest Post Shortcode Slider
latest-post-shortcode-slider-extension
The plugin is an extension for the Latest Post Shortcode plugin, and allows you to output the static or dynamical selection you make as a responsive s …
TinyMCE shortcode Addon
360crest-themeone-tinymce-shortcodes
Foreigncodes Tinymce Shortcodes, is a wordpress tinymce addon, that jazz up your wordpress post with cool design.
Featured Post Carousel by Tag
featured-post-carousel-tag
Muestra entradas, páginas, productos y otros tipos de contenido personalizado por etiqueta en un carrusel responsive con OwlCarousel2.
WP Shortcodes Plugin — Shortcodes Ultimate Developer Profile
4 plugins · 400K total installs
How We Detect WP Shortcodes Plugin — Shortcodes Ultimate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcodes-ultimate/css/admin.css/wp-content/plugins/shortcodes-ultimate/js/about/index.js/wp-content/plugins/shortcodes-ultimate/vendor/freemius/start.phphttps://player.vimeo.com/api/player.jsshortcodes-ultimate/style.css?ver=shortcodes-ultimate/js/about/index.js?ver=shortcodes-ultimate/css/admin.css?ver=HTML / DOM Fingerprints
su-btnsu-shortcodesu-sectionsu-tabssu-accordionsu-spoilersu-slidersu-carousel+56 moredata-su-iddata-su-titledata-su-contentdata-su-typedata-su-widthdata-su-height+171 morewindow.vimeo