CVE-2026-105316
Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
| Vendor | unknown |
| Product | magee shortcodes |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown magee shortcodes
Be the first to know when new unknown vulnerabilities affecting unknown magee shortcodes are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Magee Shortcodes
0 โค 2.1.1
References
Credits
Enrico Marcolini Claudio Marchesini Dottor Marc WPScan