EIP-2026-113780

PRE-CVE

WordPress Plugin GD Star Rating - 'votes' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113780. PoCs published by anonymous.

AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in the GD Star Rating WordPress plugin. It leverages unsanitized user input in the 'votes' parameter to extract user credentials (nicename, email, login, password) from the 'wp_users' table via a UNION-based SQLi attack.

Description

WordPress Plugin GD Star Rating - 'votes' SQL Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · textwebappsphp
https://www.exploit-db.com/exploits/35835

The exploit demonstrates an SQL injection vulnerability in the GD Star Rating WordPress plugin. It leverages unsanitized user input in the 'votes' parameter to extract user credentials (nicename, email, login, password) from the 'wp_users' table via a UNION-based SQLi attack.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: GD Star Rating plugin for WordPress (version not specified)
Auth required
Prerequisites: Valid WordPress nonce · GD Star Rating plugin installed and active
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026