CVE-2023-29386

CRITICAL

Julien Crego Manager <2.0 - Unrestricted Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-29386. PoCs published by vigilante-1337.

AI-analyzed exploit summary This repository documents CVE-2023-29386, an unauthenticated arbitrary file upload vulnerability in the Manager for Icomoon WordPress plugin (versions < 2.1). The writeup includes details on exploitation, impact, and mitigation, but does not contain actual exploit code.

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.

Exploits (1)

nomisec WRITEUP
by vigilante-1337 · poc
https://github.com/vigilante-1337/CVE-2023-29386

This repository documents CVE-2023-29386, an unauthenticated arbitrary file upload vulnerability in the Manager for Icomoon WordPress plugin (versions < 2.1). The writeup includes details on exploitation, impact, and mitigation, but does not contain actual exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Manager for Icomoon WordPress plugin < 2.1
No auth needed
Prerequisites: Access to the vulnerable WordPress plugin upload endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.1
EPSS 0.0076
EPSS Percentile 50.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
Julien Crego/Manager for Icomoon < 2.0
Published Mar 26, 2024
Tracked Since Feb 18, 2026