Published : August 5, 2026

CVE-2026-8790: Football Pool <= 2.13.4 Authenticated (Subscriber+) Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE ID CVE-2026-8790
Plugin football-pool
Severity Medium (CVSS 6.1)
CWE 79
Vulnerable Version 2.13.4
Patched Version 2.13.5
Disclosed August 3, 2026

Analysis Overview

Atomic Edge analysis of CVE-2026-8790:

This vulnerability is a reflected cross-site scripting (XSS) flaw in the Football Pool plugin for WordPress, affecting all versions up to and including 2.13.4. The issue resides in the Shoutbox widget, specifically in the `widget-football-pool-shoutbox.php` file. The vulnerability arises from improper handling of the `shouttext` POST parameter, which is echoed into a `