Executive brief
The Sudoku Shortcode plugin for WordPress, which allows site owners to embed Sudoku puzzles on their pages, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into the website through the plugin's settings. These scripts will then run automatically in the browsers of any visitors who view the affected pages, potentially leading to unauthorized actions or data theft.
Technical details
The Sudoku Shortcode plugin for WordPress (versions up to 1.0.0) is vulnerable to Stored Cross-Site Scripting (XSS) due to a failure to properly sanitize and escape the 'background' parameter within the 'sudoku-sc' shortcode. This vulnerability is classified as CWE-79. An authenticated attacker with Contributor-level permissions or higher can exploit this by embedding malicious JavaScript into a page via the shortcode. Because the input is stored and later rendered without adequate security filtering, the script executes in the context of any user's session who visits the compromised page. This can lead to session hijacking or unauthorized administrative actions if a high-privileged user views the page.
Affected products
- tibouille Sudoku Shortcode <= 1.0.0
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory
References
- https://plugins.trac.wordpress.org/browser/sudoku-shortcode/tags/1.0.0/sudoku-shortcode.php
- https://plugins.trac.wordpress.org/browser/sudoku-shortcode/tags/1.0.0/sudoku-shortcode.php
- https://plugins.trac.wordpress.org/browser/sudoku-shortcode/trunk/sudoku-shortcode.php
- https://plugins.trac.wordpress.org/browser/sudoku-shortcode/trunk/sudoku-shortcode.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/99e4b38c-f81d-4578-a623-ea62495e934d?source=cve