EIP-2026-113509
PRE-CVEWordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113509. PoCs published by gx1.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated function injection vulnerability in multiple WordPress themes using the Epsilon Framework. It leverages the `epsilon_framework_ajax_action` AJAX endpoint to call arbitrary static methods, such as `Requests::request_multiple`, enabling SSRF, DoS, or DDoS amplification attacks.
Description
Wordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection
Exploits (1)
This exploit demonstrates an unauthenticated function injection vulnerability in multiple WordPress themes using the Epsilon Framework. It leverages the `epsilon_framework_ajax_action` AJAX endpoint to call arbitrary static methods, such as `Requests::request_multiple`, enabling SSRF, DoS, or DDoS amplification attacks.