EIP-2026-114355
PRE-CVEWordPress Theme This Way - 'upload_settings_image.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114355. PoCs published by Bet0.
AI-analyzed exploit summary This PHP script exploits an arbitrary file upload vulnerability in the This Way Theme for WordPress by sending a POST request with a local file to the vulnerable endpoint. The lack of input sanitization allows an attacker to upload and potentially execute arbitrary code on the server.
Description
WordPress Theme This Way - 'upload_settings_image.php' Arbitrary File Upload
Exploits (1)
This PHP script exploits an arbitrary file upload vulnerability in the This Way Theme for WordPress by sending a POST request with a local file to the vulnerable endpoint. The lack of input sanitization allows an attacker to upload and potentially execute arbitrary code on the server.