EIP-2026-113750
PRE-CVEWordPress Plugin Firestats 1.0.2 - Multiple Cross-Site Scripting / Authentication Bypass Vulnerabilities (1)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113750. PoCs published by MustLive.
AI-analyzed exploit summary This is a functional XSS exploit targeting the FireStats WordPress plugin. It leverages an authentication bypass and XSS vulnerability by submitting a crafted POST request to the ajax-handler.php endpoint, executing arbitrary JavaScript in the context of the affected site.
Description
WordPress Plugin Firestats 1.0.2 - Multiple Cross-Site Scripting / Authentication Bypass Vulnerabilities (1)
Exploits (1)
This is a functional XSS exploit targeting the FireStats WordPress plugin. It leverages an authentication bypass and XSS vulnerability by submitting a crafted POST request to the ajax-handler.php endpoint, executing arbitrary JavaScript in the context of the affected site.