Atomic Edge@atomicedgeWAFPoC
The post references a proof‑of‑concept for CVE‑2026‑2602 affecting WordPress Twentig 1.9.7 with a medium severity rating, but does not provide exploit code, active attacks, or patch information.
VulDB 🛡@vuldbActive Exploitation
The text indicates that attacker activity toward the Twentig Supercharged Block Editor Plugin (CVE‑2026‑2602) has increased, suggesting ongoing exploitation in the wild.
CVEarity@CVEarityGeneral
The tweet announces a newly listed CVE-2026-2602 affecting WordPress, noting its severity, but provides no technical details, PoC, or exploit information.
CVE@CVEnewDisclosure
The Twentig WordPress plugin is disclosed to have a stored XSS flaw in versions up to 1.9.7 via the featuredImageSizeWidth parameter, as recorded in CVE-2026-2602.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
Alert identifies CVE-2026-2602 as an authenticated stored XSS vulnerability in Twentig theme up to 1.9.7, affecting Contributor+ users through the 'featuredImageSizeWidth' field.