Stored Cross-Site Scripting in WP Shortcode Plugin by MyThemeShop
CVE-2026-9635

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-9635?

The WP Shortcode plugin by MyThemeShop is vulnerable to Stored Cross-Site Scripting, allowing authenticated users with contributor-level access or higher to inject malicious web scripts through the 'title' parameter of the [tab] shortcode. This occurs because the mts_tabs() function fails to adequately sanitize input and escape output, leading to direct injection of untrusted content into HTML between anchor tags. When users access the infected pages, the scripts can execute, posing significant risks to site integrity and user security.

Affected Version(s)

WP Shortcode by MyThemeShop 0 <= 1.4.17

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.