CVE-2026-105322: Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form
Published Oct 7, 2026
·Updated
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
Affected Software
1 affected component
Mageewp Magee Shortcodes<=2.1.1
Event History
Oct 7, 2026
CVE Published
via MITRE·06:47 AM
Data Sourced
via MITRE·06:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote user can exploit the affected contact-form actions. No account or user interaction is required.
2
What can an attacker do with a vulnerable site?
An attacker can use the site as a mail relay to send arbitrary emails to addresses they choose. The available data indicates an integrity impact, rather than confidentiality or availability impact.
3
Which plugin versions are affected?
Magee Shortcodes through version 2.1.1 is affected.