Executive brief
The Shortcodely plugin for WordPress, which provides shortcode functionality for site content, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into website pages. These scripts execute automatically when other users, including site administrators, visit the affected pages. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.
Technical details
The Shortcodely plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to a failure to properly sanitize and escape the 'widget_area' parameter. This vulnerability exists in all versions up to and including 1.0.1. An authenticated attacker with at least contributor-level permissions can exploit this by injecting arbitrary web scripts into a page. Because the payload is stored on the server, the script will execute in the browser of any user who navigates to the compromised page. This is classified as CWE-79 and allows for potential session hijacking or unauthorized administrative actions if a high-privileged user views the content.
Affected products
- Shortcodely Shortcodely Up to, and including, 1.0.1
Timeline
- 2026-05-12: disclosed: Vulnerability published to NVD
References
- https://plugins.trac.wordpress.org/browser/shortcodely/tags/1.0.1/shortcodely.php
- https://plugins.trac.wordpress.org/browser/shortcodely/tags/1.0.1/shortcodely.php
- https://plugins.trac.wordpress.org/browser/shortcodely/tags/1.0.1/shortcodely.php
- https://plugins.trac.wordpress.org/browser/shortcodely/trunk/shortcodely.php
- https://plugins.trac.wordpress.org/browser/shortcodely/trunk/shortcodely.php
- https://plugins.trac.wordpress.org/browser/shortcodely/trunk/shortcodely.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/08ef43cc-42ea-43bd-a590-4f9b2c719491?source=cve