EIP-2026-114095
PRE-CVEWordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114095. PoCs published by Murat DEMİRCİ.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the WordPress plugin 'Contact Form by Supsystic' version 1.7.18. The vulnerability allows an attacker to inject malicious JavaScript code into the 'label' field of a form, which executes when the form is viewed.
Description
WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS)
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in the WordPress plugin 'Contact Form by Supsystic' version 1.7.18. The vulnerability allows an attacker to inject malicious JavaScript code into the 'label' field of a form, which executes when the form is viewed.