EIP-2026-113528

PRE-CVE

WordPress Plugin Acunetix WP Security Plugin 3.0.3 - Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113528. PoCs published by Johto Robbie.

AI-analyzed exploit summary This is a technical writeup describing a stored XSS vulnerability in Acunetix WP Security 3.0.3, where malicious scripts can be injected into WordPress search content and logged in the Acunetix Secure WordPress plugin. The exploit leverages improper input sanitization in the search functionality.

Description

WordPress Plugin Acunetix WP Security Plugin 3.0.3 - Cross-Site Scripting

Exploits (1)

exploitdb WRITEUP
by Johto Robbie · textwebappsphp
https://www.exploit-db.com/exploits/39761

This is a technical writeup describing a stored XSS vulnerability in Acunetix WP Security 3.0.3, where malicious scripts can be injected into WordPress search content and logged in the Acunetix Secure WordPress plugin. The exploit leverages improper input sanitization in the search functionality.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Acunetix WP Security 3.0.3
No auth needed
Prerequisites: Access to a vulnerable WordPress instance with the Acunetix WP Security plugin installed
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026