Stored Cross-Site Scripting in DeMomentSomTres Shortcodes for WordPress
CVE-2026-8885
6.4MEDIUM
What is CVE-2026-8885?
The DeMomentSomTres Shortcodes plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to exploit insufficient input sanitization and output escaping. Specifically, through the 'callout' shortcode, attackers can inject arbitrary web scripts into HTML style attributes. This script runs whenever a user accesses affected pages, posing serious security risks to both site administrators and visitors.
Affected Version(s)
DeMomentSomTres Shortcodes 0 <= 1.1.1