Junglewise Threat Intelligence

CVE-2026-11598: Shortcodify WordPress plugin stored XSS in name shortcode attribute

CVE-2026-11598 · Severity: medium · CVSS 5 · Published 2026-07-28

Executive brief

Shortcodify is a WordPress plugin used to simplify the creation and management of custom shortcodes for website content. A security flaw in this plugin allows users with basic contributor-level access to embed malicious scripts into website pages. When other users, including site administrators or visitors, view these pages, the scripts could execute, potentially leading to unauthorized actions or the theft of sensitive information.

Technical details

The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to a failure to properly sanitize and escape the 'name' attribute within its shortcode implementation. This vulnerability is classified as CWE-79. An authenticated attacker with at least contributor-level permissions can inject arbitrary JavaScript or HTML into a page via a shortcode. Because the payload is stored in the database and rendered without proper escaping, the script executes in the context of any user who views the affected page. The vulnerability exists in all versions up to and including 1.4.3.

Affected products

  • lrnz Shortcodify up to, and including, 1.4.3

Timeline

  • 2026-07-28: disclosed: Vulnerability published by Wordfence and NVD

References