Junglewise Threat Intelligence

CVE-2026-7661: WordPress Bootstrap Shortcode Stored XSS in box shortcode

CVE-2026-7661 · Severity: medium · CVSS 6.4 · Published 2026-05-12

Executive brief

The Bootstrap Shortcode plugin for WordPress, which allows users to easily add Bootstrap-styled elements to their site, contains a security flaw. This vulnerability allows users with basic contributor-level access to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.

Technical details

The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'box' shortcode in all versions up to, and including, 1.0. The root cause is insufficient input sanitization and output escaping on user-supplied attributes within the shortcode implementation. An authenticated attacker with Contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into a post or page. These scripts will execute in the context of a user's browser whenever they navigate to the affected page. The plugin was temporarily closed on the WordPress repository pending review as of May 2026.

Affected products

  • Shamim_D Bootstrap Shortcode up to, and including, 1.0

Timeline

  • 2026-05-06: other: Plugin temporarily closed on WordPress.org repository
  • 2026-05-12: disclosed: CVE published by Wordfence/NVD

References