PatchSiren cyber security CVE debrief
CVE-2026-0738 gn_themes CVE debrief
The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Vendor
- gn_themes
- Product
- WP Shortcodes Plugin — Shortcodes Ultimate
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-04
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-04
- Advisory updated
- 2026-07-24
Who should care
Users of the WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress, particularly those with author level access and above, should update to a version beyond 7.4.8 to prevent potential Stored Cross-Site Scripting attacks. This is crucial for operators managing WordPress sites with the plugin installed, as it helps protect against authenticated attackers injecting malicious scripts. The update should be prioritized by platform administrators and security teams to mitigate potential risks.
Technical summary
The vulnerability exists in the su_carousel shortcode of the WP Shortcodes Plugin - Shortcodes Ultimate. Insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field allow authenticated attackers with author level access or higher to inject arbitrary web scripts. These scripts will execute when a user accesses an injected page, potentially leading to unauthorized actions or data exposure.
Defensive priority
Medium priority due to the CVSS score of 6.4 and the potential for authenticated attackers to inject malicious scripts.
Recommended defensive actions
- Update the WP Shortcodes Plugin - Shortcodes Ultimate to a version beyond 7.4.8.
- Restrict access to the plugin's functionality for users with author level access and above.
- Monitor for suspicious activity related to the su_carousel shortcode and 'su_slide_link' attachment meta field.
- Implement additional security measures such as Content Security Policy (CSP) to mitigate XSS attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-04-04T08:16:06.210Z and was last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD entries, which may not reflect the full scope of affected systems or versions. Defenders should verify the vulnerability's impact on their specific environments and monitor for suspicious activity related to the su_carousel shortcode and 'su_slide_link' attachment meta field.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-04T08:16:06.210Z and has not been modified since then. The NVD entry is currently Deferred.