{"id":"CVE-2026-85113","published":"2026-09-21T09:17:06.040","lastModified":"2026-09-21T15:17:32.737","description":"The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-74"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/b092c718-9a29-4153-894f-47892e7ba423/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to execute arbitrary shortcodes by nesting them, potentially leading to remote code execution or data leakage.","exploitability":"Exploitation requires a user to be able to inject shortcode content, which may be feasible through comments or other public inputs.","blast_radius":"If exploited, the impact could range from unauthorized access to sensitive information to full site compromise.","remediation":"Update GiveWP WordPress plugin to version 4.16.9 or later immediately.","tags":["rce","web","wp-plugin","shortcode"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:19:09.492Z"}}