EIP-2026-113695
PRE-CVEWordPress Plugin Duplicator 0.5.14 - SQL Injection / Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113695. PoCs published by Claudio Viviani.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WordPress Duplicator <= 0.5.14 via the 'duplicator_delid' parameter in the 'duplicator_package_delete' function. The PoC includes a crafted POST request to trigger a time-based SQL injection, confirming the vulnerability.
Description
WordPress Plugin Duplicator 0.5.14 - SQL Injection / Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in WordPress Duplicator <= 0.5.14 via the 'duplicator_delid' parameter in the 'duplicator_package_delete' function. The PoC includes a crafted POST request to trigger a time-based SQL injection, confirming the vulnerability.