EIP-2026-113801

PRE-CVE

WordPress Plugin GRAND Flash Album Gallery 0.55 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113801. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary The exploit demonstrates SQL injection and file content disclosure vulnerabilities in the GRAND Flash Album Gallery WordPress plugin. The SQLi occurs via the 'pid' parameter in hitcounter.php, while the file disclosure is achieved through the 'want2Read' parameter in news.php.

Description

WordPress Plugin GRAND Flash Album Gallery 0.55 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/16947

The exploit demonstrates SQL injection and file content disclosure vulnerabilities in the GRAND Flash Album Gallery WordPress plugin. The SQLi occurs via the 'pid' parameter in hitcounter.php, while the file disclosure is achieved through the 'want2Read' parameter in news.php.

Classification
Working Poc 90%
Attack Type
Sqli | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: GRAND Flash Album Gallery WordPress plugin 0.55
No auth needed
Prerequisites: Access to the vulnerable WordPress plugin endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026