EIP-2026-113957

PRE-CVE

WordPress Plugin PHP Event Calendar - 'cid' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113957. PoCs published by Ashiyane Digital Security Team.

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in the PHP Event Calendar plugin for WordPress, where unsanitized user input in the 'cid' parameter can be exploited to manipulate SQL queries. No actual exploit code is present, only a description and example URL.

Description

WordPress Plugin PHP Event Calendar - 'cid' SQL Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ashiyane Digital Security Team · textwebappsphp
https://www.exploit-db.com/exploits/38018

The provided text describes an SQL injection vulnerability in the PHP Event Calendar plugin for WordPress, where unsanitized user input in the 'cid' parameter can be exploited to manipulate SQL queries. No actual exploit code is present, only a description and example URL.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: PHP Event Calendar plugin for WordPress (version not specified)
No auth needed
Prerequisites: Access to the vulnerable endpoint · WordPress site with the affected plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026