EIP-2026-113549
PRE-CVEWordPress Plugin Ajax Load More < 2.8.2 - Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113549. PoCs published by PizzaHatHacker.
AI-analyzed exploit summary This Metasploit module exploits an authenticated arbitrary file upload vulnerability in the WordPress plugin ajax-load-more versions < 2.8.2. It logs in using valid credentials, retrieves a nonce, uploads a malicious PHP payload, and triggers it to achieve remote code execution.
Description
WordPress Plugin Ajax Load More < 2.8.2 - Arbitrary File Upload
Exploits (1)
This Metasploit module exploits an authenticated arbitrary file upload vulnerability in the WordPress plugin ajax-load-more versions < 2.8.2. It logs in using valid credentials, retrieves a nonce, uploads a malicious PHP payload, and triggers it to achieve remote code execution.