CVE-2013-5961

Lazy SEO 1.1.9 - Unauthenticated Arbitrary File Upload and Remote Code Execution via lazyseo.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-5961. PoCs published by Ashiyane Digital Security Team.

AI-analyzed exploit summary This is a writeup describing a shell upload vulnerability in the WordPress Lazy SEO plugin (version 1.1.9). It outlines steps to exploit the vulnerability by uploading a shell via the lazyseo.php file.

Description

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ashiyane Digital Security Team · textwebappsphp
https://www.exploit-db.com/exploits/28452

This is a writeup describing a shell upload vulnerability in the WordPress Lazy SEO plugin (version 1.1.9). It outlines steps to exploit the vulnerability by uploading a shell via the lazyseo.php file.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Lazy SEO plugin 1.1.9
No auth needed
Prerequisites: Access to the vulnerable lazyseo.php file · A shell file to upload
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87384
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/28452
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/97662

Scores

EPSS 0.0545
EPSS Percentile 91.7%

Details

Status published
Products (1)
danny_morris/lazy_seo 1.1.9
Published Sep 30, 2013
Tracked Since Feb 18, 2026