CVE-2024-11227
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_accordion shortcode in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<h4>Shortcodes to enhance the appearance of your membership site</h4>
<p>For sites running the <a href="https://www.paidmembershipspro.com/themes/memberlite/" rel="nofollow ugc">Memberlite Theme</a> or a Memberlite Child Theme, this plugin offers several shortcodes to simplify the use of various display elements and enhance the appearance of your site content.</p>
<p><a href="https://www.paidmembershipspro.com/themes/memberlite/" rel="nofollow ugc">Memberlite</a> is the ideal theme for your <a href="https://www.paidmembershipspro.com" rel="nofollow ugc">Paid Memberships Pro</a> site. It’s fully customizable with your logo, colors, fonts, custom sidebars, and more global layout settings.</p>
<h4>[memberlite_accordion] Shortcode</h4>
<p>Add an accordion block with collapsible sections using this simple shortcode. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/accordion/" rel="nofollow ugc">more info</a></p>
<h4>[memberlite_banner] Shortcode</h4>
<p>Create fluid-width banners to divide and highlight sections of content. You can define the background as an included theme color (primary, secondary, action, or body) or any hex color. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/banners/" rel="nofollow ugc">more info</a></p>
<h4>[memberlite_btn] Shortcode</h4>
<p>Add formatted buttons with the link URL, text, style, class, target, size, and optional icon. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/buttons/" rel="nofollow ugc">more info</a></p>
<h4>[memberlite_msg] Shortcode</h4>
<p>Insert a stylized contextual message block with styling for default, info, alert, error, or a success message. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/contextual-messages/" rel="nofollow ugc">more info</a></p>
<h4>[memberlite_recent_posts] Shortcode</h4>
<p>Designed to be used on the homepage, this shortcode displays the newest posts or a defined category of posts accoriding to your shortcode settings. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/recent-posts/" rel="nofollow ugc">more info</a></p>
<h4>[memberlite_subpagelist] Shortcode</h4>
<p>Easily create a digest view of a given pages’ subpages, with an excerpt or the full page content, in the order you define. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/subpagelist/" rel="nofollow ugc">more info</a></p>
<h4>[memberlite_tabs] and [memberlite_tab] Shortcode</h4>
<p>Add a tabbed content block with this simple shortcode. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/tabs/" rel="nofollow ugc">more info</a></p>
<h4>[row] and [col] Shortcodes</h4>
<p>Format your content in responsive columns based on a 12 column grid. You can nest columns by using the [row_row] and [col_col] shortcodes. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/column-shortcodes/" rel="nofollow ugc">more info</a></p>
<h4>[fa] Shortcode</h4>
<p>Easily add any Font Awesome icon using this simple shortcode. <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/font-awesome-icons/" rel="nofollow ugc">more info</a></p>
<p>Full documentation on all included shortcodes can be found at <a href="https://www.paidmembershipspro.com/documentation/memberlite/memberlite-shortcodes/" rel="nofollow ugc">the Memberlite Theme homepage</a></p>