EIP-2026-113558
PRE-CVEWordPress Plugin All-in-One Video Gallery plugin 2.4.9 - Local File Inclusion (LFI)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113558. PoCs published by Mohamed Magdy Abumusilm.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the WordPress All-in-One Video Gallery plugin (version <= 2.4.9). The vulnerability is triggered via the 'tab' parameter in an authenticated context, allowing path traversal to access arbitrary files.
Description
WordPress Plugin All-in-One Video Gallery plugin 2.4.9 - Local File Inclusion (LFI)
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the WordPress All-in-One Video Gallery plugin (version <= 2.4.9). The vulnerability is triggered via the 'tab' parameter in an authenticated context, allowing path traversal to access arbitrary files.