EIP-2026-114255
PRE-CVEWordPress Plugin Wp-ImageZoom - 'file' Remote File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114255. PoCs published by Sammy FORGIT.
AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in Wp-ImageZoom for WordPress, allowing an attacker to read arbitrary local files by manipulating the 'file' parameter in the download.php script. The provided URL example shows how to access the /etc/passwd file.
Description
WordPress Plugin Wp-ImageZoom - 'file' Remote File Disclosure
Exploits (1)
The exploit demonstrates a directory traversal vulnerability in Wp-ImageZoom for WordPress, allowing an attacker to read arbitrary local files by manipulating the 'file' parameter in the download.php script. The provided URL example shows how to access the /etc/passwd file.