Description
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
Published: 2026-10-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Mail Relay
Action: Update Plugin
AI Analysis

Impact

The Magee Shortcodes plugin does not enforce recipient restrictions on its public contact-form actions, allowing anyone with site access to specify any email address. This lack of control enables the site to be used as an anonymous mail relay, facilitating spam, phishing, or other malicious email campaigns. The weakness stems from missing validation and authorization checks, representing improper input validation and lack of authorization safeguards.

Affected Systems

The flaw affects Version 2.1.1 or earlier of the Magee Shortcodes WordPress plugin. Any WordPress site running the plugin within this version range is vulnerable. No explicit CPE strings are supplied; the vendor identifies the product simply as Magee Shortcodes, and the exposure applies to the standard contact-form functionality provided by the plugin.

Risk and Exploitability

The reported CVSS score of 5.3 indicates a medium risk level, reflecting limited scope to the contact-form component but a readily exploitable input. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits yet. Nevertheless, because the attack requires no authentication or privileges, an attacker can trigger the mail relay from any location, making it an attractive vector for spammers. The impact is moderate: it does not compromise system integrity, but it can lead to reputational damage and potential email blacklist risk.

Generated by OpenCVE AI on October 7, 2026 at 08:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Magee Shortcodes plugin to the latest available version (≥2.1.2).
  • Disable or remove the unauthenticated contact-form feature on the site or require authentication to use the form.
  • Configure a web application firewall or server-side filter to reject form submissions that specify recipient addresses outside an approved whitelist.

Generated by OpenCVE AI on October 7, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Wed, 07 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
Title Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:47:52.583Z

Reserved: 2026-10-05T07:59:05.108Z

Link: CVE-2026-105322

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:59.507

Modified: 2026-10-07T07:16:59.507

Link: CVE-2026-105322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:30:15Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-284

    Improper Access Control