EIP-2026-114140
PRE-CVEWordPress Plugin Ultimate Product Catalogue - SQL Injection (1)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114140. PoCs published by Felipe Molina.
AI-analyzed exploit summary This is a technical writeup detailing an unauthenticated SQL injection vulnerability in the Ultimate Product Catalogue WordPress plugin (versions < 3.1.2). The vulnerability exists in the 'Item_ID' POST parameter due to improper sanitization in the 'Process_Ajax.php' file, allowing arbitrary SQL execution.
Description
WordPress Plugin Ultimate Product Catalogue - SQL Injection (1)
Exploits (1)
This is a technical writeup detailing an unauthenticated SQL injection vulnerability in the Ultimate Product Catalogue WordPress plugin (versions < 3.1.2). The vulnerability exists in the 'Item_ID' POST parameter due to improper sanitization in the 'Process_Ajax.php' file, allowing arbitrary SQL execution.