EIP-2026-113822

PRE-CVE

WordPress Plugin Image Export 1.1.0 - Arbitrary File Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113822. PoCs published by AMAR^SHG.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in the WordPress image-export plugin, allowing an attacker to download arbitrary files (e.g., wp-config.php) via a crafted GET request. The vulnerability also includes a file deletion component due to the unlink() function, which could lead to denial of service.

Description

WordPress Plugin Image Export 1.1.0 - Arbitrary File Disclosure

Exploits (1)

exploitdb WORKING POC
by AMAR^SHG · textwebappsphp
https://www.exploit-db.com/exploits/39584

This exploit demonstrates a directory traversal vulnerability in the WordPress image-export plugin, allowing an attacker to download arbitrary files (e.g., wp-config.php) via a crafted GET request. The vulnerability also includes a file deletion component due to the unlink() function, which could lead to denial of service.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress image-export plugin (all versions including 1.1.0)
No auth needed
Prerequisites: Access to the download.php file via HTTP GET request
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026