EIP-2026-113618
PRE-CVEWordPress Plugin Candidate Application Form 1.0 - Arbitrary File Download
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113618. PoCs published by Larry W. Cashdollar.
AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in the 'candidate-application-form' WordPress plugin (v1.0) via the 'downloadpdffile.php' script, which allows unauthenticated remote file download by manipulating the 'fileName' and 'fileUrl' GET parameters.
Description
WordPress Plugin Candidate Application Form 1.0 - Arbitrary File Download
Exploits (1)
The exploit demonstrates a directory traversal vulnerability in the 'candidate-application-form' WordPress plugin (v1.0) via the 'downloadpdffile.php' script, which allows unauthenticated remote file download by manipulating the 'fileName' and 'fileUrl' GET parameters.