Junglewise Threat Intelligence

CVE-2026-8885: DeMomentSomTres Shortcodes Stored XSS in callout shortcode

CVE-2026-8885 · Severity: medium · CVSS 6.4 · Published 2026-06-02

Executive brief

The DeMomentSomTres Shortcodes plugin for WordPress, which provides custom layout elements for website content, contains a security flaw. This vulnerability allows users with basic contributor-level access to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts execute automatically, potentially leading to unauthorized actions or data theft.

Technical details

The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the st_callout() function. Specifically, the 'width' and 'align' attributes of the 'callout' shortcode are concatenated directly into an HTML style attribute without proper neutralization. An authenticated attacker with contributor-level permissions or higher can exploit this by crafting a shortcode with malicious payloads in these attributes. When the page is rendered, the script executes in the context of the victim's browser. The vulnerability exists in all versions up to and including 1.1.1.

Affected products

  • DeMomentSomTres DeMomentSomTres Shortcodes Up to, and including, 1.1.1

Timeline

  • 2026-06-02: disclosed: Initial publication of the vulnerability advisory.
  • 2026-06-02: advisory: NVD and Wordfence published details regarding CVE-2026-8885.

References