EIP-2026-113645
PRE-CVEWordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113645. PoCs published by Gaetano Perrone.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated stored XSS vulnerability in WordPress Plugin Contact Form Entries versions prior to 1.1.7. The attack involves injecting malicious JavaScript via the HTTP_CLIENT_IP header, which is stored in the database and executed when an administrator views the entry.
Description
WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated)
Exploits (1)
This exploit demonstrates an unauthenticated stored XSS vulnerability in WordPress Plugin Contact Form Entries versions prior to 1.1.7. The attack involves injecting malicious JavaScript via the HTTP_CLIENT_IP header, which is stored in the database and executed when an administrator views the entry.