EIP-2026-113729
PRE-CVEWordPress Plugin Events Calendar - SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113729. PoCs published by AkkuS.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in the WordPress Plugin Events Calendar (version 1.0) via the 'month' and 'year' parameters in AJAX queries. It includes payloads for boolean-based blind, time-based blind, and UNION-based SQL injection attacks.
Description
WordPress Plugin Events Calendar - SQL Injection
Exploits (1)
exploitdb
WORKING POC
by AkkuS · textwebappsphp
https://www.exploit-db.com/exploits/44785
The exploit demonstrates SQL injection vulnerabilities in the WordPress Plugin Events Calendar (version 1.0) via the 'month' and 'year' parameters in AJAX queries. It includes payloads for boolean-based blind, time-based blind, and UNION-based SQL injection attacks.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
WordPress Plugin Events Calendar 1.0
No auth needed
Prerequisites:
Access to the vulnerable plugin endpoint
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026