Known Vulnerabilities for Query Shortcode by Shazdeh
Listed below are 10 of the newest known vulnerabilities associated with "Query Shortcode" by "Shazdeh".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-9200 json | The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 vi... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-7048 json | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injec... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-3618 json | The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute... | Not Provided | 2026-04-08 | 2026-04-13 |
| CVE-2026-2363 json | The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpm... | Not Provided | 2026-03-04 | 2026-04-08 |
| CVE-2024-12473 json | The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatG... | Not Provided | 2025-01-10 | 2026-04-08 |
| CVE-2024-11430 json | The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' shortcode ... | Not Provided | 2024-12-12 | 2026-04-08 |
| CVE-2024-6479 json | The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribu... | Not Provided | 2024-10-31 | 2026-04-08 |
| CVE-2024-5605 json | The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter with... | Not Provided | 2024-06-20 | 2026-04-08 |
| CVE-2024-5031 json | The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including,... | Not Provided | 2024-05-22 | 2026-04-08 |
| CVE-2024-4743 json | The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy attr... | Not Provided | 2024-06-05 | 2026-04-08 |