EIP-2026-114295
PRE-CVEWordPress Plugin Zingiri Web Shop 2.2.0 - Remote File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114295. PoCs published by Ben Schmidt.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the Zingiri Web Shop WordPress plugin. The vulnerable code unsafely includes a file path provided via the 'wpabspath' parameter without proper validation, allowing an attacker to include arbitrary remote files.
Description
WordPress Plugin Zingiri Web Shop 2.2.0 - Remote File Inclusion
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the Zingiri Web Shop WordPress plugin. The vulnerable code unsafely includes a file path provided via the 'wpabspath' parameter without proper validation, allowing an attacker to include arbitrary remote files.