The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-284 |
Wed, 07 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay). | |
| Title | Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-07T06:47:52.583Z
Reserved: 2026-10-05T07:59:05.108Z
Link: CVE-2026-105322
No data.
Status : Received
Published: 2026-10-07T07:16:59.507
Modified: 2026-10-07T07:16:59.507
Link: CVE-2026-105322
No data.
OpenCVE Enrichment
Updated: 2026-10-07T08:30:15Z