EIP-2026-113969
PRE-CVEWordPress Plugin Plg Novana - 'id' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113969. PoCs published by sil3nt.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in the Plg Novana plugin, where user-supplied input via the 'id' parameter in 'novana_detail.php' is not properly sanitized. This allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.
Description
WordPress Plugin Plg Novana - 'id' SQL Injection
Exploits (1)
The provided text describes an SQL injection vulnerability in the Plg Novana plugin, where user-supplied input via the 'id' parameter in 'novana_detail.php' is not properly sanitized. This allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.