CVE-2026-85113

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-21: 109-21
Referenced assets1 URL
Full discourse1 post
  • NewNormal Security@NewScanTeam

    NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 21 Sep 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🔗 Host-header injection — the app builds its own download and asset links from a header you send, so every link can be aimed at the attacker (Eclipse Open VSX CVE-2025-12999) 📦 Unauthenticated file upload in a vulnerable plugin build — any visitor uploads a script and runs code (WooCommerce Online Product Designer CVE-2026-82187) 📦 Vulnerable WordPress plugin builds — shortcode injection, client-set order prices, unauthenticated import (GiveWP CVE-2026-85113, RestroPress CVE-2026-85010, To Do List Member CVE-2026-86802) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #HostHeaderInjection #CSO #REDTEAM

    0000055
    7 followersView on X

Explore more