EIP-2026-113593
PRE-CVEWordPress Plugin Best Web Soft Captcha 4.1.5 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113593. PoCs published by Colette Chamberland.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the BWS Captcha WordPress plugin (version <=4.1.5) due to unsanitized input in the 's' parameter of whitelist.php. The PoC shows how an attacker can craft a malicious URL or form to execute arbitrary JavaScript in the context of an authenticated admin user.
Description
WordPress Plugin Best Web Soft Captcha 4.1.5 - Multiple Vulnerabilities
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in the BWS Captcha WordPress plugin (version <=4.1.5) due to unsanitized input in the 's' parameter of whitelist.php. The PoC shows how an attacker can craft a malicious URL or form to execute arbitrary JavaScript in the context of an authenticated admin user.