EIP-2026-114067
PRE-CVEWordPress Plugin Slideshow - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114067. PoCs published by waraxe.
AI-analyzed exploit summary The exploit demonstrates multiple reflected XSS vulnerabilities in the Slideshow plugin for WordPress by injecting malicious scripts via unsanitized input parameters in various endpoints. The PoC includes crafted URLs that trigger arbitrary JavaScript execution in the context of the affected site.
Description
WordPress Plugin Slideshow - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates multiple reflected XSS vulnerabilities in the Slideshow plugin for WordPress by injecting malicious scripts via unsanitized input parameters in various endpoints. The PoC includes crafted URLs that trigger arbitrary JavaScript execution in the context of the affected site.