EIP-2026-114136
PRE-CVEWordPress Plugin Ultimate Product Catalog 3.8.1 - Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114136. PoCs published by i0akiN SEC-LABORATORY.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in WordPress Ultimate Product Catalog <=3.8.1. It allows users with contributor, editor, or author roles to escalate their privileges to administrator by sending a crafted POST request to the vulnerable `access_role` parameter.
Description
WordPress Plugin Ultimate Product Catalog 3.8.1 - Privilege Escalation
Exploits (1)
This exploit demonstrates a privilege escalation vulnerability in WordPress Ultimate Product Catalog <=3.8.1. It allows users with contributor, editor, or author roles to escalate their privileges to administrator by sending a crafted POST request to the vulnerable `access_role` parameter.