Description
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Cross-site Scripting (Reflected)
Action: Immediate Patch
AI Analysis

Impact

The Magee Shortcodes WordPress plugin, versions up to 2.1.1, fails to sanitize and escape data received through certain AJAX actions. These actions, including live_preview and magee_create_shortcode, are accessible to users without authentication. When unfiltered user input is reflected back in the server response, an attacker can embed malicious JavaScript that executes in the browser of any visitor who accesses the affected action URL. This flaw is an example of CWE‑79, where input is not properly neutralized before inclusion in web page output.

Affected Systems

Any WordPress site using the Magee Shortcodes plugin version 2.1.1 or earlier is affected. The exact vendor is listed as Unknown:Magee Shortcodes, so this applies to all installations of the plugin regardless of where it is sourced.

Risk and Exploitability

The vulnerability allows attackers to execute arbitrary scripts in a user’s browser when they interact with the affected AJAX actions, potentially stealing session cookies or injecting phishing content. Since the actions are available to unauthenticated users, exploitation does not require prior access. No CVSS score is provided, and the EPSS score is not available, but the nature of the flaw suggests a high exploitation risk. The vulnerability is not listed in CISA’s KEV catalog as of the current data. Attackers can trigger it simply by constructing a crafted request to one of the vulnerable endpoints.

Generated by OpenCVE AI on October 7, 2026 at 07:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Magee Shortcodes plugin to the latest version (>'2.1.1') which includes proper input sanitization and escaping for the affected AJAX actions.
  • If an upgrade is not immediately possible, disable or block access to the live_preview and magee_create_shortcode AJAX endpoints by configuring the web server or a security plugin to reject unauthenticated requests to these URLs.
  • Implement input validation by ensuring that all data sent to these AJAX actions is either strictly typed or filtered against a whitelist, and enforce output escaping when generating responses in the plugin code.

Generated by OpenCVE AI on October 7, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
Title Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:06.476Z

Reserved: 2026-10-05T07:35:09.220Z

Link: CVE-2026-105316

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:59.403

Modified: 2026-10-07T07:16:59.403

Link: CVE-2026-105316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')