EIP-2026-114108

PRE-CVE

WordPress Plugin Tagged Albums - 'id' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114108. PoCs published by Ashiyane Digital Security Team.

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in the Tagged Albums WordPress plugin, where unsanitized user input in the 'id' parameter of image.php can be exploited to manipulate SQL queries. No actual exploit code is present, only a description and example URL.

Description

WordPress Plugin Tagged Albums - 'id' SQL Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ashiyane Digital Security Team · textwebappsphp
https://www.exploit-db.com/exploits/38023

The provided text describes an SQL injection vulnerability in the Tagged Albums WordPress plugin, where unsanitized user input in the 'id' parameter of image.php can be exploited to manipulate SQL queries. No actual exploit code is present, only a description and example URL.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Tagged Albums WordPress plugin (version not specified)
No auth needed
Prerequisites: Access to the vulnerable WordPress plugin endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026