EIP-2026-114328
PRE-CVEWordPress Theme flashnews - Multiple Input Validation Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114328. PoCs published by MustLive.
AI-analyzed exploit summary The exploit demonstrates multiple input-validation vulnerabilities in the flashnews WordPress theme, including XSS and arbitrary file upload/execution via the `thumb.php` and `test.php` endpoints. The provided URLs showcase how an attacker can inject malicious scripts or upload arbitrary files.
Description
WordPress Theme flashnews - Multiple Input Validation Vulnerabilities
Exploits (1)
The exploit demonstrates multiple input-validation vulnerabilities in the flashnews WordPress theme, including XSS and arbitrary file upload/execution via the `thumb.php` and `test.php` endpoints. The provided URLs showcase how an attacker can inject malicious scripts or upload arbitrary files.