EIP-2026-113543
PRE-CVEWordPress Plugin Advanced Video 1.0 - Local File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113543. PoCs published by evait security GmbH.
AI-analyzed exploit summary This exploit leverages an arbitrary file download vulnerability in the Advanced Video Embed WordPress plugin (v1.0) via the 'thumb' parameter in an unauthenticated admin-ajax.php request. It reads the wp-config.php file by exploiting the file_get_contents() function in the vulnerable code.
Description
WordPress Plugin Advanced Video 1.0 - Local File Inclusion
Exploits (1)
This exploit leverages an arbitrary file download vulnerability in the Advanced Video Embed WordPress plugin (v1.0) via the 'thumb' parameter in an unauthenticated admin-ajax.php request. It reads the wp-config.php file by exploiting the file_get_contents() function in the vulnerable code.