EIP-2026-113774
PRE-CVEWordPress Plugin Frontend Upload - Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113774. PoCs published by Daniel Godoy.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in the Frontend Upload WordPress plugin, allowing attackers to upload PHP files with malicious extensions (e.g., c99.php) to execute arbitrary code on the server.
Description
WordPress Plugin Frontend Upload - Arbitrary File Upload
Exploits (1)
exploitdb
WORKING POC
by Daniel Godoy · textwebappsphp
https://www.exploit-db.com/exploits/31570
This exploit demonstrates an arbitrary file upload vulnerability in the Frontend Upload WordPress plugin, allowing attackers to upload PHP files with malicious extensions (e.g., c99.php) to execute arbitrary code on the server.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
Frontend Upload WordPress Plugin
No auth needed
Prerequisites:
Access to the WordPress plugin's upload functionality
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026