EIP-2026-114175
PRE-CVEWordPress Plugin VideoWhisper Video Presentation 3.17 - 'vw_upload.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114175. PoCs published by Sammy FORGIT.
AI-analyzed exploit summary This PHP script exploits an arbitrary file upload vulnerability in the VideoWhisper Video Presentation WordPress plugin (CVE-2026-156829). It uses cURL to upload a malicious file ('lo.php.gif') to the vulnerable endpoint, bypassing sanitization due to insufficient input validation.
Description
WordPress Plugin VideoWhisper Video Presentation 3.17 - 'vw_upload.php' Arbitrary File Upload
Exploits (1)
This PHP script exploits an arbitrary file upload vulnerability in the VideoWhisper Video Presentation WordPress plugin (CVE-2026-156829). It uses cURL to upload a malicious file ('lo.php.gif') to the vulnerable endpoint, bypassing sanitization due to insufficient input validation.