Wordpress Alert: Stored cross-site scripting in shortcodes

Untrusted shortcode attributes become executable HTML or JavaScript. A page view can run attacker-controlled script.

What it looks like

Untrusted shortcode attributes become executable HTML or JavaScript.

Why it matters

A page view can run attacker-controlled script.

What to check

Review shortcode output and escape attributes, URLs, and text separately.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress output escaping.