Stored Cross-Site Scripting in WP Shortcode Plugin by MyThemeShop
CVE-2026-9635
6.4MEDIUM
What is CVE-2026-9635?
The WP Shortcode plugin by MyThemeShop is vulnerable to Stored Cross-Site Scripting, allowing authenticated users with contributor-level access or higher to inject malicious web scripts through the 'title' parameter of the [tab] shortcode. This occurs because the mts_tabs() function fails to adequately sanitize input and escape output, leading to direct injection of untrusted content into HTML between anchor tags. When users access the infected pages, the scripts can execute, posing significant risks to site integrity and user security.
Affected Version(s)
WP Shortcode by MyThemeShop 0 <= 1.4.17