CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105316
HIGHCVSS 7.1NVD feed
Published 7 October 2026 · tracked since 8 October 2026
Description
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107204 CRITICAL 9.8
- CVE-2026-106559 MEDIUM 6.3
- CVE-2026-106560 HIGH 7.1
- CVE-2026-106561 MEDIUM 5
- CVE-2026-106563 MEDIUM 5.3
- CVE-2026-106558 HIGH 8.8
- CVE-2026-106510 HIGH 7.7
- CVE-2026-106556 HIGH 7.7
- CVE-2025-70521 CRITICAL 9.8
- CVE-2025-70518 CRITICAL 10