haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-105316.8medium[patched]

Contributor+ Stored XSS via Shortcode Attribute

TARGET ECOSYSTEM / VENDORAI Share & Summarize
AFFECTED PRODUCTAI Share & Summarize (< 2.0.4)
CWE CLASSIFICATIONCWE-79: Cross-Site Scripting
PUBLISHED DATE2026-06-03

Summary

AI Share & Summarize (< 2.0.4) does not sanitize and escape some of its shortcode attributes before outputting them onto rendered pages, allowing users with the Contributor role and above to execute Stored Cross-Site Scripting attacks.