CVE-2026-24354
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24354 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the PenciDesign Penci Shortcodes & Performance WordPress plugin. It affects all versions up to and including 6.1, with version 6.2 being the patched release. The vulnerability was reported by researcher João Pedro S Alcântara (Kinorth) on December 11, 2025, and published by Patchstack on January 10, 2026, with the CVE record received by NVD on January 22, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by CISA-ADP (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically manifesting as DOM-Based XSS. In DOM-Based XSS, malicious input is processed and rendered by the client-side JavaScript within the browser's DOM without adequate sanitization, rather than being reflected or stored server-side. Exploitation requires the attacker to have at least Contributor-level privileges on the WordPress site, and successful exploitation also requires a privileged user to interact with a crafted payload (e.g., clicking a malicious link or visiting a crafted page) (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, redirection to malicious sites, or defacement of web content visible to site visitors. The impact spans confidentiality, integrity, and limited availability, as reflected in the CVSS score (Patchstack).

Exploitability

No evidence of active in-the-wild exploitation or public proof-of-concept exploit code has been reported for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites, though this specific issue is rated low priority (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Penci Shortcodes & Performance plugin at version 6.1 or earlier, using tools like WPScan or by inspecting plugin directories.
  2. Obtain required access: Acquire at least Contributor-level credentials on the target WordPress site, either through credential stuffing, phishing, or registration if open.
  3. Craft malicious payload: Create a shortcode or page content containing a DOM-Based XSS payload that exploits the plugin's insufficient input sanitization in client-side JavaScript processing.
  4. Deliver payload: Publish or embed the crafted content in a post, page, or widget accessible to higher-privileged users (e.g., administrators or editors).
  5. Trigger execution: Induce a privileged user to visit the page containing the malicious content, causing the injected JavaScript to execute in their browser context, potentially enabling session token theft or unauthorized administrative actions (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual POST or GET requests to pages containing Penci Shortcodes plugin content from low-privileged user accounts; repeated access to shortcode-rendered pages by contributor-level accounts.
  • File System: Unexpected modifications to plugin files in wp-content/plugins/penci-shortcodes/; presence of obfuscated JavaScript in post or page content stored in the WordPress database.
  • Network: Outbound requests from victim browsers to unknown external domains following interaction with plugin-rendered pages, potentially indicating data exfiltration via XSS.
  • Application: Unusual admin account activity (e.g., new admin user creation, plugin installations) shortly after a privileged user visits affected content, suggesting successful session hijacking.

Mitigation and workarounds

The vendor has released version 6.2 of the Penci Shortcodes & Performance plugin, which addresses this vulnerability. Site administrators should update the plugin to version 6.2 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the WordPress plugin repository. If an immediate update is not possible, restricting Contributor-level user registration and limiting access to shortcode-enabled content areas can reduce exposure. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management