EIP-2026-114078

PRE-CVE

Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114078. PoCs published by Ron Jost.

AI-analyzed exploit summary This exploit demonstrates a Remote Code Execution (RCE) vulnerability in the WordPress Plugin SP Project & Document Manager before version 4.22. It leverages a case-insensitive file extension check to upload a malicious PHP file (shell.pHP) and achieve code execution on the target system.

Description

Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated)

Exploits (1)

exploitdb WORKING POC
by Ron Jost · pythonwebappsphp
https://www.exploit-db.com/exploits/50115

This exploit demonstrates a Remote Code Execution (RCE) vulnerability in the WordPress Plugin SP Project & Document Manager before version 4.22. It leverages a case-insensitive file extension check to upload a malicious PHP file (shell.pHP) and achieve code execution on the target system.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Plugin SP Project & Document Manager < 4.22
Auth required
Prerequisites: Valid WordPress credentials · Access to the plugin's file upload functionality
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026