Stored Cross-Site Scripting Vulnerability in Simple Owl Shortcodes Plugin for WordPress
CVE-2026-6255
6.4MEDIUM
What is CVE-2026-6255?
The Simple Owl Shortcodes plugin for WordPress contains a vulnerability that allows authenticated users with contributor-level access and above to exploit Stored Cross-Site Scripting (XSS). This occurs through the 'num' attribute of the 'owls_wrapper' shortcode, where improper input sanitization and output escaping of user-supplied attributes can result in arbitrary web scripts being injected. When a user accesses a page containing such scripts, the malicious code executes, potentially compromising user data and site integrity.
Affected Version(s)
Simple Owl Shortcodes 0 <= 2.1.1