EIP-2026-114142
PRE-CVEWordPress Plugin Ultimate Product Catalogue 3.1.2 - Multiple Persistent Cross-Site Scripting / Cross-Site Request Forgery / Arbitrary File Upload Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114142. PoCs published by Felipe Molina.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Ultimate Product Catalogue plugin, including CSRF, XSS, and file upload flaws. It provides functional PoC code for CSRF-based XSS and file upload attacks, targeting WordPress administrators.
Description
WordPress Plugin Ultimate Product Catalogue 3.1.2 - Multiple Persistent Cross-Site Scripting / Cross-Site Request Forgery / Arbitrary File Upload Vulnerabilities
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Ultimate Product Catalogue plugin, including CSRF, XSS, and file upload flaws. It provides functional PoC code for CSRF-based XSS and file upload attacks, targeting WordPress administrators.