EIP-2026-114351
PRE-CVEWordPress Theme Suco - 'themify-ajax.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114351. PoCs published by DevilScreaM.
AI-analyzed exploit summary This PHP script exploits an arbitrary file upload vulnerability in the Suco WordPress theme by sending a POST request to 'themify-ajax.php' with a local file ('devilscream.php') as payload. The lack of input sanitization allows an attacker to upload and potentially execute arbitrary code on the server.
Description
WordPress Theme Suco - 'themify-ajax.php' Arbitrary File Upload
Exploits (1)
This PHP script exploits an arbitrary file upload vulnerability in the Suco WordPress theme by sending a POST request to 'themify-ajax.php' with a local file ('devilscream.php') as payload. The lack of input sanitization allows an attacker to upload and potentially execute arbitrary code on the server.