CVE-2026-57712
HIGHWordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-57712. PoCs published by incogbyte.
AI-analyzed exploit summary Unauthenticated reflected XSS in WPZOOM Portfolio plugin <= 1.4.29 via attribute breakout in the 'lightbox_caption' parameter of the 'wpzoom_load_more_items' AJAX action. The exploit injects an event handler into the rendered HTML by breaking out of a double-quoted attribute.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.
Exploits (1)
Unauthenticated reflected XSS in WPZOOM Portfolio plugin <= 1.4.29 via attribute breakout in the 'lightbox_caption' parameter of the 'wpzoom_load_more_items' AJAX action. The exploit injects an event handler into the rendered HTML by breaking out of a double-quoted attribute.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L