EIP-2026-113785
PRE-CVEWordPress Plugin Ghost 0.5.5 - Unrestricted Export Download
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113785. PoCs published by Josh Brody.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in the WordPress Export to Ghost plugin, allowing unauthenticated users to download the Ghost export file via a direct URL request. The issue is due to missing admin authentication checks in versions prior to 0.5.6.
Description
WordPress Plugin Ghost 0.5.5 - Unrestricted Export Download
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in the WordPress Export to Ghost plugin, allowing unauthenticated users to download the Ghost export file via a direct URL request. The issue is due to missing admin authentication checks in versions prior to 0.5.6.