Stored Cross-Site Scripting in Shortcodify Plugin for WordPress
CVE-2026-11598
5MEDIUM
What is CVE-2026-11598?
The Shortcodify plugin for WordPress contains a vulnerability that allows authenticated users with contributor-level access or higher to perform Stored Cross-Site Scripting (XSS) attacks. This flaw stems from inadequate input sanitization and output escaping on the 'name' Shortcode Attribute. An attacker can embed arbitrary scripts in pages using the shortcode, which will execute whenever a user accesses the compromised page, potentially leading to the theft of sensitive information or website defacement.
Affected Version(s)
Shortcodify 0 <= 1.4.3