EIP-2026-104686

PRE-CVE

WordPress Core < 5.3.x - 'xmlrpc.php' Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104686. PoCs published by roddux.

AI-analyzed exploit summary This exploit abuses WordPress XML-RPC pingback functionality via multicall to exhaust server connections, leading to a Denial-of-Service (DoS). It constructs malformed XML-RPC requests to trigger excessive resource consumption.

Description

WordPress Core < 5.3.x - 'xmlrpc.php' Denial of Service

Exploits (1)

exploitdb WORKING POC
by roddux · pythondosphp
https://www.exploit-db.com/exploits/47800

This exploit abuses WordPress XML-RPC pingback functionality via multicall to exhaust server connections, leading to a Denial-of-Service (DoS). It constructs malformed XML-RPC requests to trigger excessive resource consumption.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: WordPress <= 5.3.x
No auth needed
Prerequisites: XML-RPC enabled on target WordPress site · Network access to target
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026