EIP-2026-114233
PRE-CVEWordPress Plugin WP Sitemap Page 1.6.4 - Stored Cross-Site Scripting (XSS)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114233. PoCs published by Nikhil Kapoor.
AI-analyzed exploit summary This is a technical writeup detailing a stored XSS vulnerability in the WordPress plugin WP Sitemap Page version 1.6.4. It provides step-by-step reproduction instructions and a specific payload to trigger the vulnerability.
Description
WordPress Plugin WP Sitemap Page 1.6.4 - Stored Cross-Site Scripting (XSS)
Exploits (1)
exploitdb
WRITEUP
by Nikhil Kapoor · textwebappsphp
https://www.exploit-db.com/exploits/50268
This is a technical writeup detailing a stored XSS vulnerability in the WordPress plugin WP Sitemap Page version 1.6.4. It provides step-by-step reproduction instructions and a specific payload to trigger the vulnerability.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
WordPress Plugin WP Sitemap Page 1.6.4
Auth required
Prerequisites:
WordPress 5.8.0 installed · WP Sitemap Page plugin installed and activated · Admin access to WordPress settings
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026