EIP-2026-113722
PRE-CVEWordPress Plugin Evarisk - 'uploadPhotoApres.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113722. PoCs published by Sammy FORGIT.
AI-analyzed exploit summary This PHP script exploits an arbitrary file upload vulnerability in the Evarisk WordPress plugin (CVE-2026-136695) by sending a crafted POST request to upload a malicious PHP file. The vulnerability stems from insufficient input sanitization, allowing attackers to execute arbitrary code on the server.
Description
WordPress Plugin Evarisk - 'uploadPhotoApres.php' Arbitrary File Upload
Exploits (1)
This PHP script exploits an arbitrary file upload vulnerability in the Evarisk WordPress plugin (CVE-2026-136695) by sending a crafted POST request to upload a malicious PHP file. The vulnerability stems from insufficient input sanitization, allowing attackers to execute arbitrary code on the server.