EIP-2026-114092
PRE-CVEWordPress Plugin SuperForms 4.9 - Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114092. PoCs published by ABDO10.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in WordPress SuperForms plugin (versions <= 4.9.X) by bypassing file extension validation via the 'accept_file_types' parameter. The attacker uploads a malicious file with a '.php4' extension, leading to remote code execution.
Description
WordPress Plugin SuperForms 4.9 - Arbitrary File Upload
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in WordPress SuperForms plugin (versions <= 4.9.X) by bypassing file extension validation via the 'accept_file_types' parameter. The attacker uploads a malicious file with a '.php4' extension, leading to remote code execution.