EIP-2026-113527
PRE-CVEWordPress Plugin Activity Log 2.3.1 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113527. PoCs published by Han Sahin.
AI-analyzed exploit summary The writeup details a stored XSS vulnerability in the WordPress Activity Log plugin (version 2.3.1) via the X-Forwarded-For header, which is insufficiently sanitized and rendered in the Activity Log page. The proof of concept demonstrates the injection of a malicious script that executes when an admin views the log.
Description
WordPress Plugin Activity Log 2.3.1 - Persistent Cross-Site Scripting
Exploits (1)
The writeup details a stored XSS vulnerability in the WordPress Activity Log plugin (version 2.3.1) via the X-Forwarded-For header, which is insufficiently sanitized and rendered in the Activity Log page. The proof of concept demonstrates the injection of a malicious script that executes when an admin views the log.