EIP-2026-113746
PRE-CVEWordPress Plugin Filedownload 0.1 - 'download.php' Remote File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113746. PoCs published by Septemb0x.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in WordPress Filedownload Plugin 0.1, allowing remote attackers to disclose arbitrary files via the 'path' parameter in download.php. The provided PoC shows how to access wp-config.php using a simple path traversal sequence.
Description
WordPress Plugin Filedownload 0.1 - 'download.php' Remote File Disclosure
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in WordPress Filedownload Plugin 0.1, allowing remote attackers to disclose arbitrary files via the 'path' parameter in download.php. The provided PoC shows how to access wp-config.php using a simple path traversal sequence.