EIP-2026-113801
PRE-CVEWordPress Plugin GRAND Flash Album Gallery 0.55 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113801. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates SQL injection and file content disclosure vulnerabilities in the GRAND Flash Album Gallery WordPress plugin. The SQLi occurs via the 'pid' parameter in hitcounter.php, while the file disclosure is achieved through the 'want2Read' parameter in news.php.
Description
WordPress Plugin GRAND Flash Album Gallery 0.55 - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates SQL injection and file content disclosure vulnerabilities in the GRAND Flash Album Gallery WordPress plugin. The SQLi occurs via the 'pid' parameter in hitcounter.php, while the file disclosure is achieved through the 'want2Read' parameter in news.php.