Junglewise Threat Intelligence

CVE-2026-9200: WordPress Query Shortcode local file inclusion in shortcode function

CVE-2026-9200 · Severity: high · CVSS 7.5 · Published 2026-05-27

Vendors: Wordpress.

Executive brief

The Query Shortcode plugin for WordPress, which allows users to display content using shortcodes, contains a security flaw that allows certain logged-in users to access internal server files. An attacker with contributor-level permissions or higher could exploit this to run malicious code or steal sensitive information from the website's server. This could lead to a full takeover of the website if the attacker is able to execute arbitrary commands.

Technical details

The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion (LFI) via the shortcode function in versions up to 0.2.1. The vulnerability stems from improper control of filenames within include or require statements (CWE-98). Authenticated attackers with contributor-level access or higher can exploit this to include and execute arbitrary .php files already present on the server. If an attacker can successfully upload a malicious PHP file through other means, this vulnerability can be leveraged to achieve full remote code execution (RCE), bypass access controls, or extract sensitive data. The attack requires network access and carries a high complexity due to the requirement of specific file availability for inclusion.

Affected products

  • WordPress Query Shortcode Up to, and including, 0.2.1

Timeline

  • 2026-05-27: advisory: NVD publication date
  • 2026-05-27: disclosed: Wordfence disclosure date

References