EIP-2026-113942
PRE-CVEWordPress Plugin oQey-Gallery 0.2 - 'tbpv_domain' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113942. PoCs published by AutoSec Tools.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in the oQey-Gallery WordPress plugin by injecting malicious JavaScript via the 'tbpv_domain' parameter. The payload bypasses input sanitization and executes arbitrary script code in the context of the affected site.
Description
WordPress Plugin oQey-Gallery 0.2 - 'tbpv_domain' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in the oQey-Gallery WordPress plugin by injecting malicious JavaScript via the 'tbpv_domain' parameter. The payload bypasses input sanitization and executes arbitrary script code in the context of the affected site.