EIP-2026-114206

PRE-CVE

WordPress Plugin WP Ajax Recent Posts 1.0.1 - 'do' Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114206. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the WP Ajax Recent Posts WordPress Plugin due to improper input sanitization. The PoC URL injects arbitrary JavaScript code via the 'number' parameter, which executes in the context of the affected site.

Description

WordPress Plugin WP Ajax Recent Posts 1.0.1 - 'do' Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/35663

This exploit demonstrates a reflected XSS vulnerability in the WP Ajax Recent Posts WordPress Plugin due to improper input sanitization. The PoC URL injects arbitrary JavaScript code via the 'number' parameter, which executes in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WP Ajax Recent Posts WordPress Plugin 1.0.1
No auth needed
Prerequisites: Target site running vulnerable plugin · User interaction to visit crafted URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026