What is CVE-2026-9635?
CVE-2026-9635 involves the WP Shortcode by MyThemeShop plugin for WordPress, vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode. This vulnerability, caused by insufficient input sanitization and output escaping in the mts_tabs() function, affects versions up to 1.4.17. Users should update to the patched version or temporarily disable the plugin.
Azərbaycanca: CVE-2026-9635, WordPress üçün WP Shortcode by MyThemeShop plagini ilə bağlıdır. Zəiflik [tab] shortcode-un 'title' parametrində saxlanılan Cross-Site Scripting (Stored XSS) yaradır; bu, mts_tabs() funksiyasında daxiletmənin kifayət qədər təmizlənməməsi səbəbindən baş verir. İstifadəçilər plaginin ən son versiyasına yeniləməli və ya müvəqqəti olaraq plagini deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-9635 and where does the vulnerability occur?
The vulnerability affects the WP Shortcode by MyThemeShop plugin, specifically within the 'title' parameter of the [tab] shortcode in the mts_tabs() function.
What is the recommended mitigation for CVE-2026-9635?
Users should update to the latest version of the plugin or temporarily disable it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.