EIP-2026-114333
PRE-CVEWordPress Theme Infocus - '/infocus/lib/scripts/dl-skin.php' Local File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114333. PoCs published by Felipe Andrian Peixoto.
AI-analyzed exploit summary This exploit demonstrates a local file disclosure vulnerability in the Infocus WordPress theme by submitting a crafted POST request to 'dl-skin.php' with a malicious file path. The vulnerability allows an attacker to read arbitrary local files, such as '/etc/passwd', due to insufficient input validation.
Description
WordPress Theme Infocus - '/infocus/lib/scripts/dl-skin.php' Local File Disclosure
Exploits (1)
This exploit demonstrates a local file disclosure vulnerability in the Infocus WordPress theme by submitting a crafted POST request to 'dl-skin.php' with a malicious file path. The vulnerability allows an attacker to read arbitrary local files, such as '/etc/passwd', due to insufficient input validation.