EIP-2026-113513
PRE-CVEWordPress Plugin 1 Flash Gallery 1.30 < 1.5.7a - Arbitrary File Upload (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113513. PoCs published by Ben Schmidt.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in the '1 Flash Gallery' WordPress plugin (versions 1.30 to 1.5.7a). It uploads a malicious PHP file via a crafted POST request to the vulnerable upload.php endpoint, then triggers the payload by accessing the uploaded file.
Description
WordPress Plugin 1 Flash Gallery 1.30 < 1.5.7a - Arbitrary File Upload (Metasploit)
Exploits (1)
This Metasploit module exploits an arbitrary file upload vulnerability in the '1 Flash Gallery' WordPress plugin (versions 1.30 to 1.5.7a). It uploads a malicious PHP file via a crafted POST request to the vulnerable upload.php endpoint, then triggers the payload by accessing the uploaded file.