WPHizmet

Eklenti güvenlik geçmişi

Magee Shortcodes güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Magee Shortcodes eklentisi için 3 açık kaydı bulunuyor; en yenisi 7 Ekim 2026 tarihli. Bunların 1 tanesi kritik veya yüksek önemde, 2 tanesi oturum açmadan istismar edilebiliyor.

Bu eklenti WordPress.org dizininden kaldırılmış

Artık güncelleme almıyor; bir alternatife geçmeniz önerilir.

Toplam kayıt
3
Kritik veya yüksek
1
Oturumsuz istismar
2
Son kayıt
7 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-105322Orta · 5,37 Ekim 2026

    güvenlik

    Etkilenen sürümler: 2.1.1 ve öncesi · Oturum açmadan istismar edilebilir

    The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).

  • CVE-2026-105316Yüksek · 7,17 Ekim 2026

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.1.1 ve öncesi · Oturum açmadan istismar edilebilir

    The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.

    Türkçe kayıt ve ne yapmalı
  • CVE-2023-4783Orta · 5,416 Ekim 2023

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.1.1 ve öncesi

    The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.