MEDIUM

CVE-2026-10531

2026-06-24 CVSS v3.1
CVSS
5.4

Description

The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

Summary dbcve.org

The AI Share & Summarize WordPress plugin before version 2.0.4 fails to sanitize and escape shortcode attributes before outputting them in pages, allowing stored XSS attacks. Users with Contributor role or higher can inject malicious JavaScript via crafted shortcode attributes.

Mitigation

Update the plugin to version 2.0.4 or later which implements proper sanitization and escaping of shortcode output.

EPSS Score

0.23%
Probability of exploitation in next 30 days
13.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE