EIP-2026-104793
PRE-CVEWordPress Plugin Work The Flow - Arbitrary File Upload (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104793. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress Work The Flow plugin (version 2.5.2), allowing remote code execution via a malicious PHP file upload. The exploit leverages a multipart form data POST request to bypass restrictions and deploy a payload.
Description
WordPress Plugin Work The Flow - Arbitrary File Upload (Metasploit)
Exploits (1)
This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress Work The Flow plugin (version 2.5.2), allowing remote code execution via a malicious PHP file upload. The exploit leverages a multipart form data POST request to bypass restrictions and deploy a payload.