Known vulnerabilities in ToneDen Shortcode
Enables shortcode to embed ToneDen's widget in WordPress blogs.
4Reported vulnerabilities
7.2Highest CVSS score
1.0Latest version
2,000+Active installs
What to do now
Update ToneDen Shortcode to 1.0 or later.
Some of these have no published fix. Update to the latest version and check the vendor advisory.
This plugin has not been updated in over two years. New vulnerabilities may never be fixed. Consider an alternative.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-28158 | High | 0.2% | 358 and earlier | — | August 13, 2026 |
| CVE-2026-28156 | Medium | 0.3% | 358 and earlier | — | August 13, 2026 |
| CVE-2026-28157 | Medium | 0.4% | 358 and earlier | — | August 13, 2026 |
| CVE-2026-28155 | Medium | 0.2% | 358 and earlier | — | August 13, 2026 |