MEDIUM
CVE-2026-10531
CVSS
5.4
Description
The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Summary dbcve.org
The AI Share & Summarize WordPress plugin before version 2.0.4 fails to sanitize and escape shortcode attributes before outputting them in pages, allowing stored XSS attacks. Users with Contributor role or higher can inject malicious JavaScript via crafted shortcode attributes.
Mitigation
Update the plugin to version 2.0.4 or later which implements proper sanitization and escaping of shortcode output.
EPSS Score
0.23%
Probability of exploitation in next 30 days
13.6th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.