PatchSiren cyber security CVE debrief
CVE-2026-11597 surbma CVE debrief
The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and 'id' shortcode attributes in the surbma_infusionsoft_shortcode_shortcode() function. An authenticated attacker with contributor-level access can inject arbitrary web scripts that execute when a user accesses an injected page. The vulnerability has a CVSS score of 6.4 and a MEDIUM severity. The CVE was published on 2026-06-27T08:16:43.910Z and modified on 2026-06-29T18:40:23.203Z.
- Vendor
- surbma
- Product
- Surbma | Infusionsoft Shortcode
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-27
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-27
- Advisory updated
- 2026-06-29
Who should care
WordPress users with the Surbma | Infusionsoft Shortcode plugin installed should be aware of this vulnerability. Site administrators and security teams should prioritize updating to a patched version to prevent potential attacks. Contributors and above with access to the plugin's shortcode functionality are at risk of exploitation.
Technical summary
The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS). The vulnerability exists in the 'infusionsoft-form' shortcode, specifically in the handling of 'account' and 'id' attributes. These attributes are not properly sanitized or escaped, allowing an attacker to inject malicious scripts. The scripts are executed when a user accesses a page containing the injected shortcode. The vulnerability requires contributor-level access or higher for exploitation.
Defensive priority
Medium priority should be given to updating the Surbma | Infusionsoft Shortcode plugin to a version beyond 2.0.1. Site administrators should ensure that all contributors and users with higher access levels are aware of the risks and monitor for potential exploitation attempts.
Recommended defensive actions
- Update the Surbma | Infusionsoft Shortcode plugin to the latest version.
- Limit contributor-level access and above to trusted users.
- Monitor for suspicious shortcode usage and injected scripts.
- Implement additional security measures such as Web Application Firewall (WAF) rules to detect and prevent XSS attacks.
- Regularly review and update plugins and themes to prevent exploitation of known vulnerabilities.
Evidence notes
The CVE-2026-11597 record was obtained from the official CVE database and the National Vulnerability Database (NVD). Additional information was gathered from Wordfence security reports. The vulnerability details and CVSS score were verified through these sources.
Official resources
This article is AI-assisted and based on the supplied source corpus.