Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.5
Shortcoder: Malicious Code Can Run on Your Website
CVE-2026-27074
Summary
The Shortcoder plugin for WordPress is vulnerable to a security risk that allows attackers to inject malicious code into your website. This could lead to your website being compromised or visitors being tricked into doing something unwanted. Update to the latest version of Shortcoder to fix this issue.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vaakash Shortcoder shortcoder allows Stored XSS.This issue affects Shortcoder: from n/a through...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vaakash Shortcoder shortcoder allows Stored XSS.This issue affects Shortcoder: from n/a through <= 6.5.1.
nvd CVSS3.1
6.5
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026