Impact
The Magee Shortcodes plugin does not enforce recipient restrictions on its public contact-form actions, allowing anyone with site access to specify any email address. This lack of control enables the site to be used as an anonymous mail relay, facilitating spam, phishing, or other malicious email campaigns. The weakness stems from missing validation and authorization checks, representing improper input validation and lack of authorization safeguards.
Affected Systems
The flaw affects Version 2.1.1 or earlier of the Magee Shortcodes WordPress plugin. Any WordPress site running the plugin within this version range is vulnerable. No explicit CPE strings are supplied; the vendor identifies the product simply as Magee Shortcodes, and the exposure applies to the standard contact-form functionality provided by the plugin.
Risk and Exploitability
The reported CVSS score of 5.3 indicates a medium risk level, reflecting limited scope to the contact-form component but a readily exploitable input. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits yet. Nevertheless, because the attack requires no authentication or privileges, an attacker can trigger the mail relay from any location, making it an attractive vector for spammers. The impact is moderate: it does not compromise system integrity, but it can lead to reputational damage and potential email blacklist risk.
OpenCVE Enrichment