← back

CVE-2026-57356

HIGH · 7.1 EPSS 0.2%
hype MOSTLY HYPE · 18 hack

Pure hashtag spam recycling CVE ID; no PoC, no advisory, no real signal.

What: Unauthenticated Cross-Site Scripting (XSS) in MC Woocommerce Wishlist plugin <= 1.9.19 affecting WordPress installations (CVSS 7.1 HIGH).

Why it matters: Top 8 posts are identical templated bluesky repeats mentioning "proofofconcept" hashtag but no actual PoC link, working exploit, or vendor patch details provided. Not KEV-listed. Low EPSS (0.09%). Chatter is high-volume but entirely derivative; no defender activity or threat intel grounding the noise.

Where it's seen: Bluesky hashtag spam—eight near-identical posts with keyword stuffing (#redteam #malware #proofofconcept) but zero substantive analysis, links, or evidence of active exploitation.

RISK: MODERATE — WordPress plugin XSS warrants patching but no active exploitation confirmed.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/24/2026, 1:43:09 AM

Description

Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 3.7
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low

Weaknesses