EIP-2026-110468
PRE-CVEPapoo 1.0.3 - 'Plugin.php' Authentication Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110468. PoCs published by Nico Leidecker.
AI-analyzed exploit summary The exploit describes an authentication-bypass vulnerability in Papoo CMS, allowing unauthorized access to administration plugins via a specific URL. No actual exploit code is provided, only a description and example URL.
Description
Papoo 1.0.3 - 'Plugin.php' Authentication Bypass
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Nico Leidecker · textwebappsphp
https://www.exploit-db.com/exploits/30249
The exploit describes an authentication-bypass vulnerability in Papoo CMS, allowing unauthorized access to administration plugins via a specific URL. No actual exploit code is provided, only a description and example URL.
Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target:
Papoo CMS 3.6
No auth needed
Prerequisites:
Access to the target URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026