The Shortcodes Ultimate plugin for WordPress has a security vulnerability that allows attackers to inject harmful code into web pages. This can happen when a user with certain permissions uses the plugin’s su_tooltip feature. The vulnerability exists in all versions up to and including 7.0.2.