CVE-2026-16758: Snippet Shortcodes <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16758?
The severity of CVE-2026-16758 is classified as medium with a score of 6.4.
How do I fix CVE-2026-16758?
To fix CVE-2026-16758, update the Snippet Shortcodes plugin to version 5.2.1 or later.
What type of vulnerability is CVE-2026-16758?
CVE-2026-16758 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who can exploit CVE-2026-16758?
CVE-2026-16758 can be exploited by authenticated attackers with contributor-level access.
What are the impacts of CVE-2026-16758?
The impacts of CVE-2026-16758 include the potential for attackers to execute scripts in the context of user sessions.