EIP-2026-114302
PRE-CVEWordPress Theme Acento - 'view-pdf.php?File' Arbitrary File Download
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114302. PoCs published by alieye.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in the WordPress 'acento' theme. The vulnerability allows unauthenticated attackers to download sensitive files (e.g., wp-config.php, /etc/passwd) by manipulating the 'file' parameter in the view-pdf.php script.
Description
WordPress Theme Acento - 'view-pdf.php?File' Arbitrary File Download
Exploits (1)
This exploit demonstrates an arbitrary file download vulnerability in the WordPress 'acento' theme. The vulnerability allows unauthenticated attackers to download sensitive files (e.g., wp-config.php, /etc/passwd) by manipulating the 'file' parameter in the view-pdf.php script.