EIP-2026-113997
PRE-CVEWordPress Plugin RB Agency 2.4.7 - Local File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113997. PoCs published by Persian Hack Team.
AI-analyzed exploit summary This exploit demonstrates a local file disclosure vulnerability in the WordPress RB Agency plugin (version 2.4.7) via a path traversal attack in the 'forcedownload.php' endpoint. The PoC shows how an attacker can read arbitrary files (e.g., '/etc/passwd') by manipulating the 'file' parameter.
Description
WordPress Plugin RB Agency 2.4.7 - Local File Disclosure
Exploits (1)
This exploit demonstrates a local file disclosure vulnerability in the WordPress RB Agency plugin (version 2.4.7) via a path traversal attack in the 'forcedownload.php' endpoint. The PoC shows how an attacker can read arbitrary files (e.g., '/etc/passwd') by manipulating the 'file' parameter.