EIP-2026-113838
PRE-CVEWordPress Plugin Invit0r - 'ofc_upload_image.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113838. PoCs published by Sammy FORGIT.
AI-analyzed exploit summary This PHP script exploits an arbitrary file upload vulnerability in the Invit0r WordPress plugin (version 0.22) by sending a crafted POST request to 'ofc_upload_image.php' with a malicious PHP payload. The exploit leverages insufficient input sanitization to upload and execute arbitrary code on the target server.
Description
WordPress Plugin Invit0r - 'ofc_upload_image.php' Arbitrary File Upload
Exploits (1)
This PHP script exploits an arbitrary file upload vulnerability in the Invit0r WordPress plugin (version 0.22) by sending a crafted POST request to 'ofc_upload_image.php' with a malicious PHP payload. The exploit leverages insufficient input sanitization to upload and execute arbitrary code on the target server.