EIP-2026-114227
PRE-CVEWordPress Plugin WP Private Messages - 'msgid' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114227. PoCs published by IeDb ir.
AI-analyzed exploit summary The code describes an SQL injection vulnerability in the WP Private Messages WordPress plugin, where insufficient sanitization of user-supplied data in the 'msgid' parameter allows attackers to manipulate SQL queries. The provided URL demonstrates the injection point but lacks functional exploit code.
Description
WordPress Plugin WP Private Messages - 'msgid' SQL Injection
Exploits (1)
The code describes an SQL injection vulnerability in the WP Private Messages WordPress plugin, where insufficient sanitization of user-supplied data in the 'msgid' parameter allows attackers to manipulate SQL queries. The provided URL demonstrates the injection point but lacks functional exploit code.