EIP-2026-114083
PRE-CVEWordPress Plugin Spider Catalog 1.4.6 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114083. PoCs published by waraxe.
AI-analyzed exploit summary This is a detailed writeup describing multiple SQL injection vulnerabilities in the Spider Catalog WordPress plugin version 1.4.6. It includes proof-of-concept examples for exploiting SQLi via shortcodes and GET/POST parameters.
Description
WordPress Plugin Spider Catalog 1.4.6 - Multiple Vulnerabilities
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by waraxe · textwebappsphp
https://www.exploit-db.com/exploits/25724
This is a detailed writeup describing multiple SQL injection vulnerabilities in the Spider Catalog WordPress plugin version 1.4.6. It includes proof-of-concept examples for exploiting SQLi via shortcodes and GET/POST parameters.
Classification
Writeup 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:
Spider Catalog WordPress Plugin 1.4.6
Auth required
Prerequisites:
WordPress installation with Spider Catalog plugin · User with posting privileges for shortcode exploitation · Admin access for certain SQLi vectors
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026