Stored Cross-Site Scripting in Shortcodify Plugin for WordPress
CVE-2026-11598

5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 July 2026

What is CVE-2026-11598?

The Shortcodify plugin for WordPress contains a vulnerability that allows authenticated users with contributor-level access or higher to perform Stored Cross-Site Scripting (XSS) attacks. This flaw stems from inadequate input sanitization and output escaping on the 'name' Shortcode Attribute. An attacker can embed arbitrary scripts in pages using the shortcode, which will execute whenever a user accesses the compromised page, potentially leading to the theft of sensitive information or website defacement.

Affected Version(s)

Shortcodify 0 <= 1.4.3

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zakaria
.