EIP-2026-113740
PRE-CVEWordPress Plugin Feature Slideshow 1.0.6 - 'src' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113740. PoCs published by AutoSec Tools.
AI-analyzed exploit summary The code describes a cross-site scripting (XSS) vulnerability in the Feature Slideshow Plugin for WordPress, specifically in the 'timthumb.php' file, due to improper sanitization of user-supplied input. The vulnerability allows arbitrary script execution in the context of the affected site.
Description
WordPress Plugin Feature Slideshow 1.0.6 - 'src' Cross-Site Scripting
Exploits (1)
The code describes a cross-site scripting (XSS) vulnerability in the Feature Slideshow Plugin for WordPress, specifically in the 'timthumb.php' file, due to improper sanitization of user-supplied input. The vulnerability allows arbitrary script execution in the context of the affected site.