Stored Cross-Site Scripting Vulnerability in hk_shortcode Plugin for WordPress
CVE-2026-8886
6.4MEDIUM
What is CVE-2026-8886?
The hk_shortcode plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate sanitization and escaping of user inputs within its 'title-plane' shortcode. Specifically, when the 'title' attribute is used within the huankong_post_short_title_plane() function, it is directly included in HTML output without proper escaping. This flaw allows authenticated attackers with contributor-level access and higher to inject malicious web scripts. Any user accessing the compromised page may inadvertently execute these scripts, posing significant security risks to the site.
Affected Version(s)
hk_shortcode 0 <= 1.0