Reflected Cross-Site Scripting in EntreDroppers Plugin for WordPress
CVE-2026-8628

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 June 2026

What is CVE-2026-8628?

The EntreDroppers plugin for WordPress is exposed to a reflected cross-site scripting vulnerability caused by inadequate input sanitization and output escaping. This flaw affects all versions up to and including 1.1.2, allowing unauthenticated attackers to execute malicious scripts in affected pages. The vulnerability stems from the PHP_SELF parameter, which is directly echoed to the form action attribute without proper validation. Attackers can exploit this by tricking users into clicking on specially crafted links, resulting in the injection of arbitrary web scripts that can execute within their browsers.

Affected Version(s)

EntreDroppers 0 <= 1.1.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdulsamad Yusuf
.