CVE-2026-1851 | deckercz iVysilani Shortcode Plugin up to 3.0 on WordPress width cross site scripting
A vulnerability, which was classified as problematic, has been found in deckercz iVysilani Shortcode Plugin up to 3.0 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation of the argument width leads to cross site scripting.
This vulnerability is traded as CVE-2026-1851. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.