EIP-2026-113610
PRE-CVEWordPress Plugin BuddyPress Activity Plus 1.5 - Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113610. PoCs published by Tom Adams.
AI-analyzed exploit summary The exploit demonstrates a CSRF vulnerability in BuddyPress Activity Plus 1.5, allowing arbitrary file deletion via a crafted POST request to admin-ajax.php. The PoC includes a form that submits malicious input to delete files like wp-config.php by leveraging the bpfb_remove_temp_images action.
Description
WordPress Plugin BuddyPress Activity Plus 1.5 - Cross-Site Request Forgery
Exploits (1)
The exploit demonstrates a CSRF vulnerability in BuddyPress Activity Plus 1.5, allowing arbitrary file deletion via a crafted POST request to admin-ajax.php. The PoC includes a form that submits malicious input to delete files like wp-config.php by leveraging the bpfb_remove_temp_images action.