Junglewise Threat Intelligence

CVE-2026-6549: Logo Manager For Enamad Stored XSS in Shortcodes

CVE-2026-6549 · Severity: medium · CVSS 6.4 · Published 2026-05-20

Executive brief

The Logo Manager For Enamad plugin for WordPress, which helps site owners manage trust logos, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts will run automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft. The plugin has been temporarily closed by the WordPress directory pending a full review.

Technical details

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes. An authenticated attacker with contributor-level permissions or higher can exploit this by providing a malicious payload in the 'title' attribute. When the shortcode is rendered, the script is executed in the browser of any user visiting the page. The vulnerability affects all versions up to and including 0.7.4. The plugin was temporarily closed on the WordPress repository on May 14, 2026.

Affected products

  • Omid Shamloo Logo Manager For Enamad <= 0.7.4

Timeline

  • 2026-05-14: other: Plugin temporarily closed on WordPress.org repository
  • 2026-05-20: disclosed: NVD publication date

References