EIP-2026-114280

PRE-CVE

WordPress Plugin WPtouch 1.9.27 - URL redirection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114280. PoCs published by MaKyOtOx.

AI-analyzed exploit summary This exploit demonstrates an open redirect vulnerability in WPtouch WordPress Plugin 1.9.27. By manipulating the 'wptouch_redirect' parameter, an attacker can redirect users to an arbitrary domain, potentially facilitating phishing attacks.

Description

WordPress Plugin WPtouch 1.9.27 - URL redirection

Exploits (1)

exploitdb WORKING POC
by MaKyOtOx · textwebappsphp
https://www.exploit-db.com/exploits/17423

This exploit demonstrates an open redirect vulnerability in WPtouch WordPress Plugin 1.9.27. By manipulating the 'wptouch_redirect' parameter, an attacker can redirect users to an arbitrary domain, potentially facilitating phishing attacks.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: WPtouch WordPress Plugin 1.9.27
No auth needed
Prerequisites: Target site running WPtouch WordPress Plugin 1.9.27 · User interaction to click on the crafted URL
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026