CVE-2026-57356
HIGH · 7.1 EPSS 0.2%Pure hashtag spam recycling CVE ID; no PoC, no advisory, no real signal.
What: Unauthenticated Cross-Site Scripting (XSS) in MC Woocommerce Wishlist plugin <= 1.9.19 affecting WordPress installations (CVSS 7.1 HIGH).
Why it matters: Top 8 posts are identical templated bluesky repeats mentioning "proofofconcept" hashtag but no actual PoC link, working exploit, or vendor patch details provided. Not KEV-listed. Low EPSS (0.09%). Chatter is high-volume but entirely derivative; no defender activity or threat intel grounding the noise.
Where it's seen: Bluesky hashtag spam—eight near-identical posts with keyword stuffing (#redteam #malware #proofofconcept) but zero substantive analysis, links, or evidence of active exploitation.
RISK: MODERATE — WordPress plugin XSS warrants patching but no active exploitation confirmed.
Description
Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- Required
- Scope
- Changed
- Confidentiality
- Low
- Integrity
- Low
- Availability
- Low