EIP-2026-113674
PRE-CVEWordPress Plugin Custom Content Type Manager 0.9.5.13-pl - Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113674. PoCs published by Adrien Thierry.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in WordPress Custom Content Type Manager 0.9.5.13-pl, allowing attackers to upload malicious files disguised as images (jpg/png/gif) to achieve remote code execution (RCE). The exploit leverages a lack of proper file extension validation in the upload_form.php script.
Description
WordPress Plugin Custom Content Type Manager 0.9.5.13-pl - Arbitrary File Upload
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in WordPress Custom Content Type Manager 0.9.5.13-pl, allowing attackers to upload malicious files disguised as images (jpg/png/gif) to achieve remote code execution (RCE). The exploit leverages a lack of proper file extension validation in the upload_form.php script.