EIP-2026-113511

PRE-CVE

WordPress MU 1.2.2 < 1.3.1 - '/wp-includes/wpmu-functions.php' Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113511. PoCs published by Juan Galiana Lara.

AI-analyzed exploit summary This proof-of-concept demonstrates a stored XSS vulnerability in WordPress by injecting malicious JavaScript via the Host header in a request to profile.php. The payload is triggered when the victim opens the generated HTML file in a browser.

Description

WordPress MU 1.2.2 < 1.3.1 - '/wp-includes/wpmu-functions.php' Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by Juan Galiana Lara · textwebappsphp
https://www.exploit-db.com/exploits/10090

This proof-of-concept demonstrates a stored XSS vulnerability in WordPress by injecting malicious JavaScript via the Host header in a request to profile.php. The payload is triggered when the victim opens the generated HTML file in a browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WordPress (version not specified)
Auth required
Prerequisites: Victim must be authenticated in WordPress · Victim must open the generated HTML file
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026