Impact
The Magee Shortcodes WordPress plugin, versions up to 2.1.1, fails to sanitize and escape data received through certain AJAX actions. These actions, including live_preview and magee_create_shortcode, are accessible to users without authentication. When unfiltered user input is reflected back in the server response, an attacker can embed malicious JavaScript that executes in the browser of any visitor who accesses the affected action URL. This flaw is an example of CWE‑79, where input is not properly neutralized before inclusion in web page output.
Affected Systems
Any WordPress site using the Magee Shortcodes plugin version 2.1.1 or earlier is affected. The exact vendor is listed as Unknown:Magee Shortcodes, so this applies to all installations of the plugin regardless of where it is sourced.
Risk and Exploitability
The vulnerability allows attackers to execute arbitrary scripts in a user’s browser when they interact with the affected AJAX actions, potentially stealing session cookies or injecting phishing content. Since the actions are available to unauthenticated users, exploitation does not require prior access. No CVSS score is provided, and the EPSS score is not available, but the nature of the flaw suggests a high exploitation risk. The vulnerability is not listed in CISA’s KEV catalog as of the current data. Attackers can trigger it simply by constructing a crafted request to one of the vulnerable endpoints.
OpenCVE Enrichment