← Back to search

CVE-2026-85113

6.5 MEDIUM

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows unauthenticated users to execute arbitrary shortcodes by nesting them, potentially leading to remote code execution or data leakage.
Exploitability
Exploitation requires a user to be able to inject shortcode content, which may be feasible through comments or other public inputs.
Blast radius
If exploited, the impact could range from unauthorized access to sensitive information to full site compromise.
Prioritized remediation
Update GiveWP WordPress plugin to version 4.16.9 or later immediately.
rcewebwp-pluginshortcode

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses

CWE-74

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.