EIP-2026-114331
PRE-CVEWordPress Theme Highlight Premium - Cross-Site Request Forgery / Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114331. PoCs published by DevilScreaM.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the WordPress Highlight Premium Theme, allowing unauthenticated file uploads via a crafted form submission. The uploaded file can be accessed in the /uploads/ directory, potentially leading to remote code execution if a malicious file is uploaded.
Description
WordPress Theme Highlight Premium - Cross-Site Request Forgery / Arbitrary File Upload
Exploits (1)
This exploit demonstrates a CSRF vulnerability in the WordPress Highlight Premium Theme, allowing unauthenticated file uploads via a crafted form submission. The uploaded file can be accessed in the /uploads/ directory, potentially leading to remote code execution if a malicious file is uploaded.