Lana Shortcodes
Lana Shortcodes has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Lana Shortcodes has a vendor fix available, so running the current release closes it.
All of these findings were reported by Webbernaut. Lana Shortcodes is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.
CVE-2023-3372Lana Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records

Lana Shortcodes
Author
Lana Codes
The Lana Shortcodes are optimized for Bootstrap. The Lana Shortcodes are developed primarily for Lana themes. Video Shortcodes list: Button shortcode [lana_button size=”md” type=”primary” class=”custom-color”]Lana Button[/lana_button] Icon shortcode [lana_icon name=”home”] Label shortcode [lana_label type=”primary”]New[/lana_label] Badges shortcode [lana_badges]2[/lana_badges] Progress Bar shortcode [lana_progress_bar value=”15″ type=”primary” label=”visible” striped=”1″ active=”1″] Lana Codes Lana Shortcodes
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C