EIP-2026-114280
PRE-CVEWordPress Plugin WPtouch 1.9.27 - URL redirection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114280. PoCs published by MaKyOtOx.
AI-analyzed exploit summary This exploit demonstrates an open redirect vulnerability in WPtouch WordPress Plugin 1.9.27. By manipulating the 'wptouch_redirect' parameter, an attacker can redirect users to an arbitrary domain, potentially facilitating phishing attacks.
Description
WordPress Plugin WPtouch 1.9.27 - URL redirection
Exploits (1)
exploitdb
WORKING POC
by MaKyOtOx · textwebappsphp
https://www.exploit-db.com/exploits/17423
This exploit demonstrates an open redirect vulnerability in WPtouch WordPress Plugin 1.9.27. By manipulating the 'wptouch_redirect' parameter, an attacker can redirect users to an arbitrary domain, potentially facilitating phishing attacks.
Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target:
WPtouch WordPress Plugin 1.9.27
No auth needed
Prerequisites:
Target site running WPtouch WordPress Plugin 1.9.27 · User interaction to click on the crafted URL
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026