EIP-2026-113958
PRE-CVEWordPress Plugin PHP Speedy 0.5.2 - 'admin_container.php' Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113958. PoCs published by mr_me.
AI-analyzed exploit summary This PHP script exploits a remote code execution vulnerability in the php_speedy WordPress plugin (versions <= 0.5.2) by leveraging PHP's register_globals and allow_url_include settings to inject malicious code via the admin_container.php file. The exploit uses a ROT13-encoded payload and a php://filter stream to bypass security restrictions.
Description
WordPress Plugin PHP Speedy 0.5.2 - 'admin_container.php' Remote Code Execution
Exploits (1)
This PHP script exploits a remote code execution vulnerability in the php_speedy WordPress plugin (versions <= 0.5.2) by leveraging PHP's register_globals and allow_url_include settings to inject malicious code via the admin_container.php file. The exploit uses a ROT13-encoded payload and a php://filter stream to bypass security restrictions.