๐Ÿ” CVE Alert

CVE-2026-105316

UNKNOWN 0.0

Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.

Vendor unknown
Product magee shortcodes
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown magee shortcodes

Be the first to know when new unknown vulnerabilities affecting unknown magee shortcodes are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Magee Shortcodes
0 โ‰ค 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/8240033a-bb4b-490f-97da-4ae768d2cb6d/

Credits

Enrico Marcolini Claudio Marchesini Dottor Marc WPScan