Reflected Cross-Site Scripting in EntreDroppers Plugin for WordPress
CVE-2026-8628
6.1MEDIUM
What is CVE-2026-8628?
The EntreDroppers plugin for WordPress is exposed to a reflected cross-site scripting vulnerability caused by inadequate input sanitization and output escaping. This flaw affects all versions up to and including 1.1.2, allowing unauthenticated attackers to execute malicious scripts in affected pages. The vulnerability stems from the PHP_SELF parameter, which is directly echoed to the form action attribute without proper validation. Attackers can exploit this by tricking users into clicking on specially crafted links, resulting in the injection of arbitrary web scripts that can execute within their browsers.
Affected Version(s)
EntreDroppers 0 <= 1.1.2