Junglewise Threat Intelligence

CVE-2026-0738: GN Themes Shortcodes Ultimate Stored XSS in su_carousel shortcode

CVE-2026-0738 · Severity: medium · CVSS 6.4 · Published 2026-04-04

Executive brief

Shortcodes Ultimate, a popular WordPress plugin used to add visual elements to websites, contains a security flaw that allows users with 'Author' permissions to inject malicious scripts into pages. These scripts execute in the browser of any visitor who views the affected page or interacts with a carousel element. This could lead to unauthorized actions being performed in the visitor's session or the theft of sensitive information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Shortcodes Ultimate plugin for WordPress (versions <= 7.4.8) within the 'su_carousel' shortcode component. The root cause is insufficient input sanitization and output escaping of the 'su_slide_link' attachment meta field. An authenticated attacker with Author-level privileges or higher can inject arbitrary web scripts by crafting a malicious 'Slide link' value on a media attachment and then referencing that attachment in a carousel shortcode. When a user views the page and interacts with the carousel (e.g., a mouseover event), the script executes in their browser context. The issue is fixed in version 7.4.9.

Affected products

  • GN Themes Shortcodes Ultimate <= 7.4.8

Timeline

  • 2026-01-06: other: Vulnerability detected and reported to vendor
  • 2026-04-03: disclosed: Public disclosure of vulnerability
  • 2026-04-04: advisory: NVD publication date
  • 2026-04-04: patched: Patch released in version 7.4.9

References