EIP-2026-113555
PRE-CVEWordPress Plugin All in One SEO Pack 2.3.6.1 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113555. PoCs published by David Vaartjes.
AI-analyzed exploit summary This is a detailed technical analysis of a stored XSS vulnerability in the All in One SEO Pack WordPress Plugin (version 2.3.6.1). The vulnerability arises from improper sanitization of User-Agent and Referer headers in the Bot Blocker functionality, allowing an attacker to inject malicious scripts into the admin dashboard.
Description
WordPress Plugin All in One SEO Pack 2.3.6.1 - Persistent Cross-Site Scripting
Exploits (1)
This is a detailed technical analysis of a stored XSS vulnerability in the All in One SEO Pack WordPress Plugin (version 2.3.6.1). The vulnerability arises from improper sanitization of User-Agent and Referer headers in the Bot Blocker functionality, allowing an attacker to inject malicious scripts into the admin dashboard.