EIP-2026-113524
PRE-CVEWordPress Plugin Accept Signups 0.1 - Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113524. PoCs published by clshack.
AI-analyzed exploit summary The exploit demonstrates a persistent XSS vulnerability in the WordPress 'Accept Signups' plugin (version 0.1) due to improper sanitization of the 'email' parameter in 'accept-signups_submit.php'. The PoC injects a JavaScript payload via the 'email' GET parameter, which is stored and executed when rendered.
Description
WordPress Plugin Accept Signups 0.1 - Cross-Site Scripting
Exploits (1)
The exploit demonstrates a persistent XSS vulnerability in the WordPress 'Accept Signups' plugin (version 0.1) due to improper sanitization of the 'email' parameter in 'accept-signups_submit.php'. The PoC injects a JavaScript payload via the 'email' GET parameter, which is stored and executed when rendered.