EIP-2026-113423

PRE-CVE

Wiccle Web Builder 2.0 - Multiple Cross-Site Scripting Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113423. PoCs published by Veerendra G.G.

AI-analyzed exploit summary This exploit demonstrates multiple reflected XSS vulnerabilities in Wiccle Web Builder CMS and iWiccle CMS Community Builder by injecting arbitrary JavaScript via the 'post_text' parameter in various modules. The PoC provides URLs that trigger alert popups when user-supplied input is not properly sanitized.

Description

Wiccle Web Builder 2.0 - Multiple Cross-Site Scripting Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Veerendra G.G · textwebappsphp
https://www.exploit-db.com/exploits/34890

This exploit demonstrates multiple reflected XSS vulnerabilities in Wiccle Web Builder CMS and iWiccle CMS Community Builder by injecting arbitrary JavaScript via the 'post_text' parameter in various modules. The PoC provides URLs that trigger alert popups when user-supplied input is not properly sanitized.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Wiccle Web Builder CMS, iWiccle CMS Community Builder
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026