Stored Cross-Site Scripting Vulnerability in Surbma | Infusionsoft Shortcode Plugin for WordPress
CVE-2026-11597
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2026
What is CVE-2026-11597?
The Surbma | Infusionsoft Shortcode plugin for WordPress has a vulnerability that allows authenticated attackers to exploit insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the 'infusionsoft-form' shortcode can be manipulated through the 'account' and 'id' attributes, leading to the injection of arbitrary web scripts. When this malicious script is rendered on a page, it can execute in the context of users accessing the affected site, which could lead to further attacks or data theft.
Affected Version(s)
Surbma | Infusionsoft Shortcode 0 <= 2.0.1