EIP-2026-113927
PRE-CVEWordPress Plugin NextGEN Gallery 1.9.1 - 'photocrati_ajax' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113927. PoCs published by SANTHO.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in the NextGEN Gallery WordPress plugin, allowing attackers to upload a malicious PHP file disguised as an image. The uploaded file contains a simple command execution interface, enabling remote code execution.
Description
WordPress Plugin NextGEN Gallery 1.9.1 - 'photocrati_ajax' Arbitrary File Upload
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in the NextGEN Gallery WordPress plugin, allowing attackers to upload a malicious PHP file disguised as an image. The uploaded file contains a simple command execution interface, enabling remote code execution.