CVE-2026-105322
Received Received - Intake

Magee Shortcodes WordPress Plugin Mail Relay Vulnerability

Vulnerability report for CVE-2026-105322, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: WPScan

Description

The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Magee Shortcodes 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Magee Shortcodes WordPress plugin through version 2.1.1 has an unauthenticated mail relay vulnerability. This means unauthenticated users can send emails to any address through the site, effectively turning the website into an open mail relay without proper restrictions.

Detection Guidance

To detect this vulnerability, check if your Magee Shortcodes WordPress plugin is version 2.1.1 or below. Inspect server logs for unusual outbound email activity or unauthorized email sending attempts through the contact form.

Impact Analysis

This vulnerability allows attackers to use your website to send spam or phishing emails to any recipient. It can damage your site's reputation, lead to blacklisting by email providers, and consume server resources. Additionally, it may expose your users to malicious content sent through your domain.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR if personal data is exposed through unauthorized emails. For HIPAA, it may risk unauthorized disclosure of protected health information if emails containing such data are sent without control. Both standards require safeguards against unauthorized data transmission.

Mitigation Strategies

Immediately disable or uninstall the Magee Shortcodes plugin if you are using version 2.1.1 or below. Monitor your mail server logs for suspicious activity and consider implementing email relay restrictions on your server.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105322. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart