Medium severity5.3NVD Advisory· Published Oct 7, 2026
CVE-2026-105322
CVE-2026-105322
Description
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=2.1.1+ 1 more
- (no CPE)range: <=2.1.1
- (no CPE)range: <=2.1.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.