EIP-2026-113718

PRE-CVE

WordPress Plugin Email NewsLetter 8.0 - 'option' Information Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113718. PoCs published by Sammy FORGIT.

AI-analyzed exploit summary The exploit demonstrates an information disclosure vulnerability in the Email Newsletter WordPress plugin by leveraging insufficient user input validation in the export.php script. Attackers can retrieve sensitive user data by manipulating the 'option' parameter in the URL.

Description

WordPress Plugin Email NewsLetter 8.0 - 'option' Information Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by Sammy FORGIT · textwebappsphp
https://www.exploit-db.com/exploits/37356

The exploit demonstrates an information disclosure vulnerability in the Email Newsletter WordPress plugin by leveraging insufficient user input validation in the export.php script. Attackers can retrieve sensitive user data by manipulating the 'option' parameter in the URL.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Email Newsletter WordPress plugin 8.0
No auth needed
Prerequisites: Access to the target WordPress site with the vulnerable plugin installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026