Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-1844 — Proof-of-concept exploit for CVE-2026-1844, a stored XSS vulnerability in PixelYourSite PRO WordPress plugin, demonstrating unauthenticated script injection. | Kitploit
Tools/GitHubGitHub/adamshaikhma/cve-2026-1844
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubadamshaikhma/cve-2026-1844

CVE-2026-1844

Proof-of-concept exploit for CVE-2026-1844, a stored XSS vulnerability in PixelYourSite PRO WordPress plugin, demonstrating unauthenticated script injection.

View Repository
17 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

PixelYourSite PRO - Unauthenticated Stored Cross-Site Scripting(CVE-2026-1844)

Overview

The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 12.4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Key Points

  • Severity: Critical
  • CVSS Score: 7.2 (High)
  • Attack Vector: Network

Download here

Download Tool