EIP-2026-112064

PRE-CVE

Simple Backup Plugin Python Exploit 2.7.10 - Path Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112064. PoCs published by Ven3xy.

AI-analyzed exploit summary This exploit leverages a path traversal vulnerability in the Simple Backup Plugin for WordPress (versions < 2.7.10) to arbitrarily download files from the server. It constructs a malicious request to `/wp-admin/tools.php` with traversal sequences to access files outside the intended directory.

Description

Simple Backup Plugin Python Exploit 2.7.10 - Path Traversal

Exploits (1)

exploitdb WORKING POC
by Ven3xy · textwebappsphp
https://www.exploit-db.com/exploits/51937

This exploit leverages a path traversal vulnerability in the Simple Backup Plugin for WordPress (versions < 2.7.10) to arbitrarily download files from the server. It constructs a malicious request to `/wp-admin/tools.php` with traversal sequences to access files outside the intended directory.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Simple Backup Plugin for WordPress < 2.7.10
Auth required
Prerequisites: Access to a valid WordPress admin session · Knowledge of the target file path and name
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026