EIP-2026-114090
PRE-CVEWordPress Plugin Subscribe to Comments 2.0 - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114090. PoCs published by MustLive.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in the Subscribe to Comments WordPress plugin by injecting malicious JavaScript via the 'ref' and 'email' parameters. The PoC URLs show how attacker-supplied code can execute in the context of the affected site.
Description
WordPress Plugin Subscribe to Comments 2.0 - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in the Subscribe to Comments WordPress plugin by injecting malicious JavaScript via the 'ref' and 'email' parameters. The PoC URLs show how attacker-supplied code can execute in the context of the affected site.