EIP-2026-113717
PRE-CVEWordPress Plugin Elementor 3.6.2 - Remote Code Execution (RCE) (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113717. PoCs published by AkuCyberSec.
AI-analyzed exploit summary This exploit demonstrates an authenticated RCE vulnerability in WordPress Plugin Elementor versions 3.6.0-3.6.2 by uploading a malicious ZIP file containing a PHP payload. It requires valid credentials and leverages broken access control to execute arbitrary code.
Description
WordPress Plugin Elementor 3.6.2 - Remote Code Execution (RCE) (Authenticated)
Exploits (1)
This exploit demonstrates an authenticated RCE vulnerability in WordPress Plugin Elementor versions 3.6.0-3.6.2 by uploading a malicious ZIP file containing a PHP payload. It requires valid credentials and leverages broken access control to execute arbitrary code.