CVE-2026-1099 | Administrative Shortcodes Plugin up to 0.3.4 on WordPress Shortcode login/logout cross site scripting (EUVD-2026-4560)
A vulnerability, which was classified as problematic, has been found in Administrative Shortcodes Plugin up to 0.3.4 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation of the argument login/logout leads to cross site scripting.
This vulnerability is traded as CVE-2026-1099. It is possible to initiate the attack remotely. There is no exploit available.