EIP-2026-103341
PRE-CVEWordPress Core 4.7.0/4.7.1 - Content Injection (Ruby)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103341. PoCs published by Harsh Jaiswal.
AI-analyzed exploit summary This exploit leverages a content injection vulnerability in WordPress REST API (CVE-2017-1001000) to modify post content without authentication. It sends a crafted JSON payload to the vulnerable endpoint to update a post's title and content.
Description
WordPress Core 4.7.0/4.7.1 - Content Injection (Ruby)
Exploits (1)
exploitdb
WORKING POC
by Harsh Jaiswal · rubywebappslinux
https://www.exploit-db.com/exploits/41224
This exploit leverages a content injection vulnerability in WordPress REST API (CVE-2017-1001000) to modify post content without authentication. It sends a crafted JSON payload to the vulnerable endpoint to update a post's title and content.
Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
WordPress 4.7 - 4.7.1
No auth needed
Prerequisites:
Target must be running WordPress 4.7 - 4.7.1 · REST API must be accessible
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026