CVE-2026-9714 | creaweb2b Simple Divi Shortcode Plugin up to 1.2 on WordPress showmodule_shortcode ID cross site scripting (EUVD-2026-33252)
ID: 2635bd96-84b3-51da-b96d-92759de3b03d
STIX ID: report--2635bd96-84b3-51da-b96d-92759de3b03d
Feed Name: VulDB Recent Entries
The Simple Divi Shortcode WordPress plugin (versions up to 1.2) contains a stored cross-site scripting (XSS) vulnerability in the showmodule_shortcode handler via the 'id' shortcode attribute (CVE-2026-9714); insufficient sanitization and escaping allow authenticated contributors to inject scripts that execute when pages are viewed. The flaw was disclosed by Muhammad Yudha and published 2026-05-29; exploitation is remote but requires authenticated user interaction and no public exploit is currently available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
