EIP-2026-114304
PRE-CVEWordPress Theme Amplus - Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114304. PoCs published by DevilScreaM.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the WordPress Amplus theme, allowing unauthenticated file uploads via a crafted form submission to 'upload-handler.php'. The uploaded file can be accessed in the 'uploads' directory, potentially leading to remote code execution if a malicious script is uploaded.
Description
WordPress Theme Amplus - Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a CSRF vulnerability in the WordPress Amplus theme, allowing unauthenticated file uploads via a crafted form submission to 'upload-handler.php'. The uploaded file can be accessed in the 'uploads' directory, potentially leading to remote code execution if a malicious script is uploaded.