EIP-2026-113658

PRE-CVE

WordPress Plugin Corner Ad 1.0.7 - Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113658. PoCs published by Atik Rahman.

AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in the WordPress Corner-Ad plugin version 1.0.7. The exploit involves injecting malicious JavaScript into the 'Ad name' field, which is not properly escaped, leading to execution when the page is viewed.

Description

WordPress Plugin Corner Ad 1.0.7 - Cross-Site Scripting

Exploits (1)

exploitdb WRITEUP VERIFIED
by Atik Rahman · textwebappsphp
https://www.exploit-db.com/exploits/41376

This is a writeup describing a stored XSS vulnerability in the WordPress Corner-Ad plugin version 1.0.7. The exploit involves injecting malicious JavaScript into the 'Ad name' field, which is not properly escaped, leading to execution when the page is viewed.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WordPress Corner-Ad plugin 1.0.7
Auth required
Prerequisites: Access to WordPress admin panel · Corner-Ad plugin installed and activated
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026