EIP-2026-114082
PRE-CVEWordPress Plugin Spider Catalog 1.1 - HTML Code Injection / Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114082. PoCs published by D4NB4R.
AI-analyzed exploit summary This is a technical writeup detailing HTML code injection and XSS vulnerabilities in the WordPress Plugin Catalog (version 1.1). It describes how the 'view=showproduct' parameter allows attackers to inject malicious code via unvalidated form submissions, which are stored in the database.
Description
WordPress Plugin Spider Catalog 1.1 - HTML Code Injection / Cross-Site Scripting
Exploits (1)
This is a technical writeup detailing HTML code injection and XSS vulnerabilities in the WordPress Plugin Catalog (version 1.1). It describes how the 'view=showproduct' parameter allows attackers to inject malicious code via unvalidated form submissions, which are stored in the database.