EIP-2026-113849
PRE-CVEWordPress Plugin jRSS Widget 1.1.1 - 'url' Information Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113849. PoCs published by John Leitch.
AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in the jRSS Widget Plugin for WordPress, allowing an attacker to read arbitrary local files via a crafted URL parameter. The provided example shows how to access the 'win.ini' file by manipulating the 'url' parameter in 'proxy.php'.
Description
WordPress Plugin jRSS Widget 1.1.1 - 'url' Information Disclosure
Exploits (1)
The exploit demonstrates a directory traversal vulnerability in the jRSS Widget Plugin for WordPress, allowing an attacker to read arbitrary local files via a crafted URL parameter. The provided example shows how to access the 'win.ini' file by manipulating the 'url' parameter in 'proxy.php'.