EIP-2026-114206
PRE-CVEWordPress Plugin WP Ajax Recent Posts 1.0.1 - 'do' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114206. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the WP Ajax Recent Posts WordPress Plugin due to improper input sanitization. The PoC URL injects arbitrary JavaScript code via the 'number' parameter, which executes in the context of the affected site.
Description
WordPress Plugin WP Ajax Recent Posts 1.0.1 - 'do' Cross-Site Scripting
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the WP Ajax Recent Posts WordPress Plugin due to improper input sanitization. The PoC URL injects arbitrary JavaScript code via the 'number' parameter, which executes in the context of the affected site.