Executive brief
A vulnerability exists in the WP Shortcode by MyThemeShop plugin, which is used to add design elements like tabs and buttons to WordPress sites. An attacker with basic contributor-level access can inject malicious scripts into website pages. When other users or administrators view these pages, the scripts could execute, potentially leading to unauthorized actions or data theft.
Technical details
The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the mts_tabs() function. Specifically, the 'title' attribute of the [tab] shortcode is output directly into HTML anchor tags without being escaped. This allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts. These scripts are stored on the server and execute in the browser of any user who visits the affected page. The vulnerability affects all versions up to and including 1.4.17.
Affected products
- MyThemeShop WP Shortcode by MyThemeShop up to, and including, 1.4.17
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory