EIP-2026-114263
PRE-CVEWordPress Plugin WP-Realty - 'listing_id' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114263. PoCs published by Napsterakos.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in the WP-Realty plugin for WordPress, where the 'listing_id' parameter in the 'contact_friend' action is not properly sanitized. It includes example URLs demonstrating the vulnerability but lacks actual exploit code.
Description
WordPress Plugin WP-Realty - 'listing_id' SQL Injection
Exploits (1)
The provided text describes an SQL injection vulnerability in the WP-Realty plugin for WordPress, where the 'listing_id' parameter in the 'contact_friend' action is not properly sanitized. It includes example URLs demonstrating the vulnerability but lacks actual exploit code.