What is CVE-2026-11598?
A Stored Cross-Site Scripting vulnerability was found in the Shortcodify plugin for WordPress up to version 1.4.3. Authenticated attackers with Contributor-level access can inject arbitrary scripts via the 'name' Shortcode Attribute due to insufficient input sanitization. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: WordPress-in Shortcodify plaginində (1.4.3 daxil olmaqla) saxlanılmış XSS zəifliyi aşkar edilib. 'name' Shortcode Attribute vasitəsilə kifayət qədər input sanitization olmaması səbəbindən Contributor səviyyəli autentifikasiya olunmuş hücumçular ixtiyari skript yerləşdirə bilər. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Through which functionality in the Shortcodify plugin can CVE-2026-11598 be exploited?
The vulnerability can be exploited via the `name` Shortcode Attribute due to insufficient input sanitization.
What is the minimum privilege level required for an attacker to exploit CVE-2026-11598?
The attacker must have authenticated access at the Contributor level.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.