PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11597 surbma CVE debrief

The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and 'id' shortcode attributes in the surbma_infusionsoft_shortcode_shortcode() function. An authenticated attacker with contributor-level access can inject arbitrary web scripts that execute when a user accesses an injected page. The vulnerability has a CVSS score of 6.4 and a MEDIUM severity. The CVE was published on 2026-06-27T08:16:43.910Z and modified on 2026-06-29T18:40:23.203Z.

Vendor
surbma
Product
Surbma | Infusionsoft Shortcode
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-27
Original CVE updated
2026-06-29
Advisory published
2026-06-27
Advisory updated
2026-06-29

Who should care

WordPress users with the Surbma | Infusionsoft Shortcode plugin installed should be aware of this vulnerability. Site administrators and security teams should prioritize updating to a patched version to prevent potential attacks. Contributors and above with access to the plugin's shortcode functionality are at risk of exploitation.

Technical summary

The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS). The vulnerability exists in the 'infusionsoft-form' shortcode, specifically in the handling of 'account' and 'id' attributes. These attributes are not properly sanitized or escaped, allowing an attacker to inject malicious scripts. The scripts are executed when a user accesses a page containing the injected shortcode. The vulnerability requires contributor-level access or higher for exploitation.

Defensive priority

Medium priority should be given to updating the Surbma | Infusionsoft Shortcode plugin to a version beyond 2.0.1. Site administrators should ensure that all contributors and users with higher access levels are aware of the risks and monitor for potential exploitation attempts.

Recommended defensive actions

  • Update the Surbma | Infusionsoft Shortcode plugin to the latest version.
  • Limit contributor-level access and above to trusted users.
  • Monitor for suspicious shortcode usage and injected scripts.
  • Implement additional security measures such as Web Application Firewall (WAF) rules to detect and prevent XSS attacks.
  • Regularly review and update plugins and themes to prevent exploitation of known vulnerabilities.

Evidence notes

The CVE-2026-11597 record was obtained from the official CVE database and the National Vulnerability Database (NVD). Additional information was gathered from Wordfence security reports. The vulnerability details and CVSS score were verified through these sources.

Official resources

This article is AI-assisted and based on the supplied source corpus.