
CVE-2026-0594 List Site Contributors Plugin Exploit
CVE-2026-0594 is a critical Reflected Cross-Site Scripting (XSS) vulnerability found in the List Site Contributors WordPress plugin. This exploit automates the discovery of vulnerable endpoints via the WordPress REST API (wp-json) and executes a specialized payload through the alpha parameter.
By leveraging this vulnerability, an attacker can:
CVE-2026-0594.go file on your system.To run the exploit, navigate to the project directory and use the following command:
go run CVE-2026-0594.go
