EIP-2026-113978
PRE-CVEWordPress Plugin Powerhouse Museum Collection Image Grid 0.9.1.1 - 'tbpv_username' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113978. PoCs published by AutoSec Tools.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in the Powerhouse Museum Collection Image Grid Plugin for WordPress by injecting arbitrary JavaScript via the 'tbpv_username' parameter. The payload is delivered through a crafted URL, executing in the context of the affected site.
Description
WordPress Plugin Powerhouse Museum Collection Image Grid 0.9.1.1 - 'tbpv_username' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in the Powerhouse Museum Collection Image Grid Plugin for WordPress by injecting arbitrary JavaScript via the 'tbpv_username' parameter. The payload is delivered through a crafted URL, executing in the context of the affected site.