Sceawere

Vulnerability Detail

CVE-2026-105322UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Magee Shortcodes Unauthenticated Email Relay

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Unknown
Product
Magee Shortcodes
Attack Type
CWE-472 External Control of Assumed-Immutable Web Parameter
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-07T07:16:59.507Z",
  "pubdate": "2026-10-07T07:16:59.507Z",
  "executiveSummary": "The Magee Shortcodes WordPress plugin, in all versions up to and including 2.1.1, contains an unauthenticated email relay vulnerability.\nThis flaw allows remote, unauthenticated attackers to leverage the web server to send arbitrary emails to any address.\nThe vulnerability stems from improper input validation and a lack of access controls on contact-form related actions within the plugin's codebase.\nBy manipulating specific request parameters, an attacker can bypass intended security constraints, utilizing the host site as an open mail relay.\nThe potential impact of this vulnerability is significant, as it facilitates mass unsolicited email (spam) campaigns, phishing attempts, and potential server reputation damage.\nThe attack requires no authentication or special privileges, allowing any remote user with network access to the target WordPress instance to trigger the malicious functionality.\nOrganizations relying on this plugin are at risk of having their mail servers blacklisted by anti-spam organizations due to abuse originating from their domain.",
  "technicalDetails": "The vulnerability originates in the Magee Shortcodes plugin's handling of contact-form submission actions. The plugin fails to enforce proper authorization checks or input validation on the backend functions responsible for processing form data and dispatching emails.\nSpecifically, the plugin exposes unauthenticated AJAX or POST action handlers that accept user-supplied input to define the recipient email address, subject, and body content without verifying the legitimacy of the request or the intended recipient.\nIn a standard deployment, the attacker identifies the endpoint associated with the plugin's contact form actions. Because the plugin does not validate that the request originated from a legitimate user session or a authorized contact form, the attacker can craft a HTTP POST request containing malicious recipient fields.\nThe attack flow follows these steps: 1) The attacker discovers the exposed action endpoint through static analysis or web traffic interception. 2) The attacker crafts a request payload where the 'to' or 'recipient' parameter is modified to point to an arbitrary email address. 3) The attacker submits this request to the server without providing any session cookies or authentication tokens. 4) The plugin backend, lacking a check for authenticated state or a pre-defined whitelist of recipients, processes the input directly. 5) The server's wp_mail() function is then called with the user-supplied parameters, effectively turning the site into an open relay.\nThis vulnerability is particularly severe because the plugin executes the email dispatch using the server’s local mail transport or SMTP configuration. Consequently, the emails appear to originate from the legitimate domain of the affected WordPress site, increasing the likelihood of successful social engineering or phishing attacks. There is no requirement for user interaction, as the relay can be triggered via automated scripts.\nThe affected component is the contact form processing module, specifically the functions handling form submissions which fail to implement nonces or administrative permission checks. Because the vulnerability exists at the application layer, it persists regardless of the underlying server configuration, provided the WordPress environment permits email functionality."
}
CVE-2026-105322: Magee Shortcodes Unauthenticated Email Relay (MEDIUM Severity, CVSS: 5.3) | Sceawere