What is CVE-2026-16758?
CVE-2026-16758 is a Stored Cross-Site Scripting vulnerability found in the 'Snippet Shortcodes' plugin for WordPress. The flaw exists in versions up to and including 5.2.0 via Shortcode Attributes due to insufficient input sanitization and output escaping, affecting authenticated users with contributor-level access. Users should update to the latest patched version or temporarily disable the plugin.
Azərbaycanca: CVE-2026-16758, WordPress-in "Snippet Shortcodes" plaginində aşkar edilmiş Stored Cross-Site Scripting zəifliyidir. Zəiflik 5.2.0 və daha əvvəlki versiyalarda "Shortcode Attributes" vasitəsilə yetərsiz input sanitization və output escaping səbəbindən yaranır, contributor səviyyəli autentifikasiya olunmuş istifadəçilərə təsir göstərir. İstifadəçilər plaginini ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What level of authentication must an attacker have to exploit CVE-2026-16758 in the Snippet Shortcodes plugin?
The attacker must have contributor-level authenticated user access.
Up to what version should the Snippet Shortcodes plugin not be kept to avoid CVE-2026-16758?
Versions up to and including 5.2.0 are affected, so these versions should be updated or disabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.