EIP-2026-114083

PRE-CVE

WordPress Plugin Spider Catalog 1.4.6 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114083. PoCs published by waraxe.

AI-analyzed exploit summary This is a detailed writeup describing multiple SQL injection vulnerabilities in the Spider Catalog WordPress plugin version 1.4.6. It includes proof-of-concept examples for exploiting SQLi via shortcodes and GET/POST parameters.

Description

WordPress Plugin Spider Catalog 1.4.6 - Multiple Vulnerabilities

Exploits (1)

exploitdb WRITEUP VERIFIED
by waraxe · textwebappsphp
https://www.exploit-db.com/exploits/25724

This is a detailed writeup describing multiple SQL injection vulnerabilities in the Spider Catalog WordPress plugin version 1.4.6. It includes proof-of-concept examples for exploiting SQLi via shortcodes and GET/POST parameters.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Spider Catalog WordPress Plugin 1.4.6
Auth required
Prerequisites: WordPress installation with Spider Catalog plugin · User with posting privileges for shortcode exploitation · Admin access for certain SQLi vectors
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026