EIP-2026-113827
PRE-CVEWordPress Plugin Import CSV 1.0 - Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113827. PoCs published by Wadeek.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in the WordPress plugin 'XML and CSV Import in Article Content' (version 1.1). By manipulating the URL field in the upload-process.php form, an attacker can traverse directories and access sensitive files like wp-config.php.
Description
WordPress Plugin Import CSV 1.0 - Directory Traversal
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in the WordPress plugin 'XML and CSV Import in Article Content' (version 1.1). By manipulating the URL field in the upload-process.php form, an attacker can traverse directories and access sensitive files like wp-config.php.