EIP-2026-113658
PRE-CVEWordPress Plugin Corner Ad 1.0.7 - Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113658. PoCs published by Atik Rahman.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in the WordPress Corner-Ad plugin version 1.0.7. The exploit involves injecting malicious JavaScript into the 'Ad name' field, which is not properly escaped, leading to execution when the page is viewed.
Description
WordPress Plugin Corner Ad 1.0.7 - Cross-Site Scripting
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Atik Rahman · textwebappsphp
https://www.exploit-db.com/exploits/41376
This is a writeup describing a stored XSS vulnerability in the WordPress Corner-Ad plugin version 1.0.7. The exploit involves injecting malicious JavaScript into the 'Ad name' field, which is not properly escaped, leading to execution when the page is viewed.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
WordPress Corner-Ad plugin 1.0.7
Auth required
Prerequisites:
Access to WordPress admin panel · Corner-Ad plugin installed and activated
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026