EIP-2026-113780
PRE-CVEWordPress Plugin GD Star Rating - 'votes' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113780. PoCs published by anonymous.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in the GD Star Rating WordPress plugin. It leverages unsanitized user input in the 'votes' parameter to extract user credentials (nicename, email, login, password) from the 'wp_users' table via a UNION-based SQLi attack.
Description
WordPress Plugin GD Star Rating - 'votes' SQL Injection
Exploits (1)
The exploit demonstrates an SQL injection vulnerability in the GD Star Rating WordPress plugin. It leverages unsanitized user input in the 'votes' parameter to extract user credentials (nicename, email, login, password) from the 'wp_users' table via a UNION-based SQLi attack.