EIP-2026-114142

PRE-CVE

WordPress Plugin Ultimate Product Catalogue 3.1.2 - Multiple Persistent Cross-Site Scripting / Cross-Site Request Forgery / Arbitrary File Upload Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114142. PoCs published by Felipe Molina.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Ultimate Product Catalogue plugin, including CSRF, XSS, and file upload flaws. It provides functional PoC code for CSRF-based XSS and file upload attacks, targeting WordPress administrators.

Description

WordPress Plugin Ultimate Product Catalogue 3.1.2 - Multiple Persistent Cross-Site Scripting / Cross-Site Request Forgery / Arbitrary File Upload Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by Felipe Molina · textwebappsphp
https://www.exploit-db.com/exploits/36907

The exploit demonstrates multiple vulnerabilities in Ultimate Product Catalogue plugin, including CSRF, XSS, and file upload flaws. It provides functional PoC code for CSRF-based XSS and file upload attacks, targeting WordPress administrators.

Classification
Working Poc 95%
Attack Type
Xss | Csrf | File Upload
Complexity
Moderate
Reliability
Reliable
Target: Ultimate Product Catalogue WordPress plugin <= 3.1.2
No auth needed
Prerequisites: Victim must visit attacker-controlled page · WordPress admin session active
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026