EIP-2026-113585
PRE-CVEWordPress Plugin BackWPUp 2.1.4 - Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113585. PoCs published by Sense of Security.
AI-analyzed exploit summary The exploit leverages a deserialization vulnerability in BackWPUp 2.1.4 via the BackWPupJobTemp POST parameter, allowing remote code execution through crafted FTP resources. The PoC demonstrates how a malicious serialized payload can be executed via require_once after being deserialized.
Description
WordPress Plugin BackWPUp 2.1.4 - Code Execution
Exploits (1)
The exploit leverages a deserialization vulnerability in BackWPUp 2.1.4 via the BackWPupJobTemp POST parameter, allowing remote code execution through crafted FTP resources. The PoC demonstrates how a malicious serialized payload can be executed via require_once after being deserialized.