CVE-2026-85113
6.5 MEDIUMPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows unauthenticated users to execute arbitrary shortcodes by nesting them, potentially leading to remote code execution or data leakage.
- Exploitability
- Exploitation requires a user to be able to inject shortcode content, which may be feasible through comments or other public inputs.
- Blast radius
- If exploited, the impact could range from unauthorized access to sensitive information to full site compromise.
- Prioritized remediation
- Update GiveWP WordPress plugin to version 4.16.9 or later immediately.
rcewebwp-pluginshortcode
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weaknesses
CWE-74
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-16623
- HIGHCVE-2026-18811PoC
- HIGHCVE-2026-18813PoC
- HIGHCVE-2026-18854
- HIGHCVE-2026-94491
- MEDIUMCVE-2026-94492PoC
- CRITICALCVE-2025-29296
- HIGHCVE-2026-12000
Related by shared AI tags and CWE weakness class. Browse the full archive.