SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81571

MEDIUM · CVSS 4.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Brave WordPress plugin prior to version 0.8.8 is vulnerable to an issue where an attacker can manipulate a URL parameter to execute arbitrary shortcodes server-side, potentially leading to unauthorized actions on the site. This vulnerability poses a medium risk, particularly for WordPress sites that utilize the Brave plugin, as it allows unauthenticated users to exploit the shortcode engine. Site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-81571
Severity
MEDIUM
CVSS
4.8
EPSS
0.15%
WordPress

Original NVD Description

The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, allowing unauthenticated attackers to have arbitrary shortcodes registered on the site executed server-side.