CVE-2026-105316 PUBLISHED

Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions

Assigner: WPScan
Reserved: 05.10.2026 Published: 07.10.2026 Updated: 07.10.2026

The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.

Product Status

Vendor Unknown
Product Magee Shortcodes
Versions Default: unknown
  • affected from 0 to 2.1.1 (incl.)

Credits

  • Enrico Marcolini finder
  • Claudio Marchesini finder
  • Dottor Marc finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE