Sceawere
Vulnerability Detail
CVE-2026-105322UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Magee Shortcodes Unauthenticated Email Relay
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Unknown
- Product
- Magee Shortcodes
- Attack Type
- CWE-472 External Control of Assumed-Immutable Web Parameter
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-07T07:16:59.507Z",
"pubdate": "2026-10-07T07:16:59.507Z",
"executiveSummary": "The Magee Shortcodes WordPress plugin, in all versions up to and including 2.1.1, contains an unauthenticated email relay vulnerability.\nThis flaw allows remote, unauthenticated attackers to leverage the web server to send arbitrary emails to any address.\nThe vulnerability stems from improper input validation and a lack of access controls on contact-form related actions within the plugin's codebase.\nBy manipulating specific request parameters, an attacker can bypass intended security constraints, utilizing the host site as an open mail relay.\nThe potential impact of this vulnerability is significant, as it facilitates mass unsolicited email (spam) campaigns, phishing attempts, and potential server reputation damage.\nThe attack requires no authentication or special privileges, allowing any remote user with network access to the target WordPress instance to trigger the malicious functionality.\nOrganizations relying on this plugin are at risk of having their mail servers blacklisted by anti-spam organizations due to abuse originating from their domain.",
"technicalDetails": "The vulnerability originates in the Magee Shortcodes plugin's handling of contact-form submission actions. The plugin fails to enforce proper authorization checks or input validation on the backend functions responsible for processing form data and dispatching emails.\nSpecifically, the plugin exposes unauthenticated AJAX or POST action handlers that accept user-supplied input to define the recipient email address, subject, and body content without verifying the legitimacy of the request or the intended recipient.\nIn a standard deployment, the attacker identifies the endpoint associated with the plugin's contact form actions. Because the plugin does not validate that the request originated from a legitimate user session or a authorized contact form, the attacker can craft a HTTP POST request containing malicious recipient fields.\nThe attack flow follows these steps: 1) The attacker discovers the exposed action endpoint through static analysis or web traffic interception. 2) The attacker crafts a request payload where the 'to' or 'recipient' parameter is modified to point to an arbitrary email address. 3) The attacker submits this request to the server without providing any session cookies or authentication tokens. 4) The plugin backend, lacking a check for authenticated state or a pre-defined whitelist of recipients, processes the input directly. 5) The server's wp_mail() function is then called with the user-supplied parameters, effectively turning the site into an open relay.\nThis vulnerability is particularly severe because the plugin executes the email dispatch using the server’s local mail transport or SMTP configuration. Consequently, the emails appear to originate from the legitimate domain of the affected WordPress site, increasing the likelihood of successful social engineering or phishing attacks. There is no requirement for user interaction, as the relay can be triggered via automated scripts.\nThe affected component is the contact form processing module, specifically the functions handling form submissions which fail to implement nonces or administrative permission checks. Because the vulnerability exists at the application layer, it persists regardless of the underlying server configuration, provided the WordPress environment permits email functionality."
}