EIP-2026-113577
PRE-CVEWordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113577. PoCs published by SunCSR Team.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in the WordPress Autoptimize plugin (v2.7.6) via the `ao_ccss_import` AJAX call, which fails to validate the uploaded file type, allowing authenticated high-privilege users to upload malicious PHP files for remote code execution (RCE).
Description
Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in the WordPress Autoptimize plugin (v2.7.6) via the `ao_ccss_import` AJAX call, which fails to validate the uploaded file type, allowing authenticated high-privilege users to upload malicious PHP files for remote code execution (RCE).