Record summary

CVE-2023-26852 has a selected CVSS score of 7.2 (high); EIP currently links 1 repository PoC.

Description

An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2025 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubleekenghwa/CVE-2023-26852-Textpattern-v4.8.8-and-Repository PoCby leekenghwaStars: 0Not analyzed6 files

1.2 MiB

GitHub

PoC details

References

4