EIP-2026-113532
PRE-CVEWordPress Plugin Add Mime Types 2.2.1 - Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113532. PoCs published by Princy Edward.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the WP Add Mime Types WordPress plugin (version <= 2.2.1). The PoC uses a malicious HTML form to automatically submit a POST request, allowing an attacker to add arbitrary MIME types (e.g., .exe) to the allowed upload list.
Description
WordPress Plugin Add Mime Types 2.2.1 - Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a CSRF vulnerability in the WP Add Mime Types WordPress plugin (version <= 2.2.1). The PoC uses a malicious HTML form to automatically submit a POST request, allowing an attacker to add arbitrary MIME types (e.g., .exe) to the allowed upload list.