Junglewise Threat Intelligence

CVE-2026-8040: WordPress faq shortocde Stored XSS in faq shortcode color attribute

CVE-2026-8040 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Executive brief

The 'faq shortocde' plugin for WordPress, which allows site owners to easily add frequently asked questions to their pages, contains a security flaw. This vulnerability allows users with basic contributor-level access to inject malicious scripts into the website. When other visitors or administrators view the affected pages, these scripts could execute, potentially leading to unauthorized actions or data theft.

Technical details

The 'faq shortocde' plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'color' attribute within the 'faq' shortcode. An authenticated attacker with Contributor-level permissions or higher can exploit this by embedding malicious JavaScript within the shortcode attribute. Because the input is stored and later rendered without proper neutralization (CWE-79), the script executes in the context of any user's browser who views the affected post or page. This vulnerability affects all versions of the plugin up to and including 1.0.

Affected products

  • WordPress plugin faq shortocde Up to, and including, 1.0

Timeline

  • 2026-05-27: disclosed: Vulnerability published on NVD
  • 2026-05-27: advisory: Wordfence advisory published

References