---
id: CVE-2026-105316
title: >-
  The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and
  escape user input in some of its AJAX actions, which are available to
  unauthenticated users, before reflecting it back in the response, leading to
  Reflected Cross-…
summary: >-
  The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and
  escape user input in some of its AJAX actions, which are available to
  unauthenticated users, before reflecting it back in the response, leading to
  Reflected Cross-…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'
cwe:
  - CWE-79
product: Magee Shortcodes
affected:
  - magee_shortcodes <= 2.1.1
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T10:17:32.800'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105316'
references:
  - url: 'https://wpscan.com/vulnerability/8240033a-bb4b-490f-97da-4ae768d2cb6d/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T09:54:00.725800Z'
ingestedAt: '2026-10-07T08:20:03.941Z'
---

## Overview

The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
