EIP-2026-113774

PRE-CVE

WordPress Plugin Frontend Upload - Arbitrary File Upload

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113774. PoCs published by Daniel Godoy.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in the Frontend Upload WordPress plugin, allowing attackers to upload PHP files with malicious extensions (e.g., c99.php) to execute arbitrary code on the server.

Description

WordPress Plugin Frontend Upload - Arbitrary File Upload

Exploits (1)

exploitdb WORKING POC
by Daniel Godoy · textwebappsphp
https://www.exploit-db.com/exploits/31570

This exploit demonstrates an arbitrary file upload vulnerability in the Frontend Upload WordPress plugin, allowing attackers to upload PHP files with malicious extensions (e.g., c99.php) to execute arbitrary code on the server.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Frontend Upload WordPress Plugin
No auth needed
Prerequisites: Access to the WordPress plugin's upload functionality
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026