← WordPress Vulnerabilities
WordPress security by component

Query Shortcode

Query Shortcode is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published May 27, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: query-shortcode

CVE-2026-9200: Query Shortcode: Filesystem traversal

Query Shortcode is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 0.2.1.

PublishedMay 27, 2026
Known safe version> 0.2.1
Safe version
May 27, 2026 CVE-2026-9200
Query Shortcode: Filesystem traversal
Query Shortcode is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 0.2.1.
> 0.2.1
CVE7.5
NVDPending