EIP-2026-114322

PRE-CVE

WordPress Theme Diary/Notebook Site5 - Email Spoofing

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114322. PoCs published by bwall.

AI-analyzed exploit summary This Perl script exploits an email spoofing vulnerability in the Diary/Notebook Site5 Wordpress Theme by sending a crafted POST request to the sendmail.php endpoint, allowing an attacker to send emails with arbitrary sender and receiver addresses.

Description

WordPress Theme Diary/Notebook Site5 - Email Spoofing

Exploits (1)

exploitdb WORKING POC VERIFIED
by bwall · perlwebappsphp
https://www.exploit-db.com/exploits/19862

This Perl script exploits an email spoofing vulnerability in the Diary/Notebook Site5 Wordpress Theme by sending a crafted POST request to the sendmail.php endpoint, allowing an attacker to send emails with arbitrary sender and receiver addresses.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Diary/Notebook Site5 Wordpress Theme (version not documented)
No auth needed
Prerequisites: Access to the target WordPress site with the vulnerable theme installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026