Stored Cross-Site Scripting in DeMomentSomTres Shortcodes for WordPress
CVE-2026-8885

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 June 2026

What is CVE-2026-8885?

The DeMomentSomTres Shortcodes plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to exploit insufficient input sanitization and output escaping. Specifically, through the 'callout' shortcode, attackers can inject arbitrary web scripts into HTML style attributes. This script runs whenever a user accesses affected pages, posing serious security risks to both site administrators and visitors.

Affected Version(s)

DeMomentSomTres Shortcodes 0 <= 1.1.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zakaria
.