EIP-2026-114190
PRE-CVEWordPress Plugin Windows Desktop and iPhone Photo Uploader - Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114190. PoCs published by Manish Tanwar.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in the WordPress plugin 'i-dump-iphone-to-wordpress-photo-uploader' due to lack of file extension validation in uploader.php. Attackers can upload malicious PHP shells to gain remote code execution.
Description
WordPress Plugin Windows Desktop and iPhone Photo Uploader - Arbitrary File Upload
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in the WordPress plugin 'i-dump-iphone-to-wordpress-photo-uploader' due to lack of file extension validation in uploader.php. Attackers can upload malicious PHP shells to gain remote code execution.