S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 15, 2025

CVE-2017-18580 Scanner

CVE-2017-18580 Scanner - Remote Code Execution (RCE) vulnerability in Shortcodes Ultimate Plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18580
9.8
CVSS

The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The WordPress Shortcodes Ultimate Plugin is a popular tool used by WordPress site administrators to enhance the functionality of their websites through a set of creative shortcodes. This plugin is often utilized by web developers and site owners looking to quickly implement custom post layouts without extensive coding. It provides various shortcodes for creating tabs, buttons, boxes, sliders, and responsive videos in posts and pages. The plugin's wide usage in the WordPress ecosystem makes it an attractive target for malicious activities, hence the importance of keeping it secure from vulnerabilities.

The vulnerability detected in this plugin allows for Remote Code Execution (RCE), which can permit attackers to execute arbitrary code on a server. This occurs due to insufficient sanitization of input data passed through specific shortcodes, potentially leading to unauthorized command execution by an attacker. The exploitation of such vulnerabilities can result in complete control over the affected WordPress site by malicious entities, endangering sensitive data and overall site integrity.

This vulnerability is triggered by a filter within the meta, post, or user shortcode that does not adequately validate incoming data. Specifically, it allows crafted shortcode data to be processed, granting the attacker the ability to run arbitrary commands on the host server. The vulnerability exists in endpoints where these shortcodes are executed, requiring careful examination of server logs and shortcode usage for detection and mitigation.

Exploitation of this vulnerability may lead to severe consequences, including unauthorized access to critical site functions and data theft. Attackers can manipulate site content, inject malware, or take down the site entirely. The risk of an RCE vulnerability is particularly high due to the potential for full server takeover, making it crucial for site administrators to address such issues promptly.

REFERENCES

Solution Advice
  • Update the Shortcodes Ultimate Plugin to version 5.0.1 or later to patch this vulnerability.
  • Regularly monitor WordPress plugins for security patches and updates to ensure the website's integrity.
  • Employ security plugins that can offer additional protection against common vulnerabilities in WordPress installations.
  • Implement a least privilege principle for user roles and access to ensure that only necessary permissions are granted.
  • Conduct regular security audits and vulnerability scans of your WordPress site to identify potential weaknesses proactively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.