
CVE-2026-1851 The iVysilani Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' shortcode attribute in all versions up to, and including, 3.0 … https://www.cve.org/CVERecord?id=CVE-2026-1851
Post summary
The iVysilani Shortcode WordPress plugin is vulnerable to stored cross‑site scripting via the 'width' attribute, with no PoC, exploit tool, or mitigation details provided.
