SoundCloud Shortcode

SoundCloud Shortcode has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for SoundCloud Shortcode has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. SoundCloud Shortcode is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all SoundCloud Shortcode vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-25936

SoundCloud Shortcode <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Read the full analysis

Vulnerability Records

2 records
SoundCloud Shortcode banner
Latestv4.0.3

SoundCloud Shortcode

indextwo

Author

indextwo

4.5(23)
90/100
Last Updated
2024-03-28 (3y ago)
Active Installs
5,000+
Downloads
417,647
Requires WP
3.1.0+
Requires PHP
5.6+
Tested up to
WP 6.4.10
Created
2009-07-10 (17y ago)

This plugin converts all SoundCloud shortcodes into embeddable SoundCloud players. It works for any SoundCloud track, playlist, user, or group. Once you install this plugin, it will work for any of your WordPress posts & pages. I mean, sure you could use oEmbed or the snappy new Gutenberg editor to simply paste in a SoundCloud URL; but we like to keep things old-school 😎 A simple example: [soundcloud]http://soundcloud.com/forss/flickermood[/soundcloud] More Options SoundCloud Shortcodes support these optional parameters: width height params The params parameter passes additional options to the SoundCloud embeddable player. You can find a full list on the SoundCloud Developers pages: https://developers.soundcloud.com/docs/api/html5-widget An example of a track that starts playing automatically, with hot-pink controls: [soundcloud params="auto_play=true&color=#F368E0"]http://soundcloud.com/forss/flickermood[/soundcloud]

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C