EIP-2026-113841

PRE-CVE

Wordpress Plugin iQ Block Country 1.2.13 - Arbitrary File Deletion via Zip Slip (Authenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113841. PoCs published by Ceylan BOZOĞULLARINDAN.

AI-analyzed exploit summary This is a technical writeup detailing a Zip Slip vulnerability in the Wordpress Plugin iQ Block Country 1.2.13, allowing authenticated users to delete arbitrary files on the server by uploading a specially crafted zip file. The vulnerability arises due to improper handling of file paths during extraction.

Description

Wordpress Plugin iQ Block Country 1.2.13 - Arbitrary File Deletion via Zip Slip (Authenticated)

Exploits (1)

exploitdb WRITEUP
by Ceylan BOZOĞULLARINDAN · textwebappsphp
https://www.exploit-db.com/exploits/50830

This is a technical writeup detailing a Zip Slip vulnerability in the Wordpress Plugin iQ Block Country 1.2.13, allowing authenticated users to delete arbitrary files on the server by uploading a specially crafted zip file. The vulnerability arises due to improper handling of file paths during extraction.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Wordpress Plugin iQ Block Country 1.2.13
Auth required
Prerequisites: Authenticated access to Wordpress admin panel · iQ Block Country plugin installed and activated
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026