Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 8 hours ago
PoC for CVE-2026-82183
The OAuth Single Sign On plugin for WordPress suffers from a significant flaw in its handling of the Steam single sign-on process. This flaw permits unauthenticated attackers to bypass authentication mechanisms, allowing them to log in as any non-administrator user. Furthermore, the vulnerability...
PoC for CVE-2026-81583
The My Login WordPress plugin prior to version 7.2.0 is susceptible to a vulnerability that fails to adhere to the network's registration settings during the sign-up process on multisite installations. This flaw permits users with subscriber accounts and even unauthenticated individuals on certai...
PoC for CVE-2026-81807
The Simple Ajax Chat plugin for WordPress, prior to version 20260827, is susceptible to a cross-site scripting vulnerability. This issue arises because the plugin fails to properly escape chat message content before it is displayed. As a result, an unauthenticated user can inject arbitrary HTML a...
PoC for CVE-2026-82182
The WPvivid Backup, Migration & Staging plugin prior to version 0.9.133 is susceptible to SQL injection due to inadequate sanitization of user-supplied identifiers in a SQL query. This vulnerability could be exploited by malicious users to execute arbitrary SQL commands, potentially compromising ...
PoC for CVE-2026-81737
The FAQ Builder AYS WordPress plugin, prior to version 1.8.5, has a vulnerability that permits unauthenticated users to submit content without proper sanitization or escaping. This leads to the potential for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be executed in the...
PoC for CVE-2026-81426
The WC Vendors plugin for WordPress, prior to version 2.7.2.1, lacks adequate protection against Cross-Site Request Forgery (CSRF) attacks on certain front-end actions related to order shipment status. This vulnerability potentially allows attackers to exploit logged-in vendor accounts to alter t...
PoC for CVE-2026-81428
The WC Vendors plugin for WordPress, prior to version 2.7.2.1, contains a critical oversight that allows authenticated users with vendor roles to manipulate product variations that do not belong to them. By exploiting this flaw, these users can alter the status and title of various posts and prod...
PoC for CVE-2026-81427
The WC Vendors plugin for WordPress prior to version 2.7.2.1 contains a significant authorization flaw. This security issue allows any authenticated vendor to modify the shipment status of orders they do not own. As a result, they can mark orders as shipped, which misrepresents their involvement ...
PoC for CVE-2026-81432
The JetStyleManager for Gutenberg WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) attacks. Specifically, versions prior to 1.3.9 lack adequate CSRF protection on certain AJAX actions. This weakness can be exploited by attackers who can deceive a logged-in user with the edit_po...
PoC for CVE-2026-81198
The MasterStudy LMS Plugin for WordPress prior to version 3.7.46 contains a vulnerability that allows authenticated users with instructor privileges to manipulate curriculum objects. This flaw occurs due to inadequate verification of ownership, enabling these users to delete or alter course secti...
PoC for CVE-2026-81199
The MasterStudy LMS WordPress Plugin prior to version 3.7.46 is susceptible to an authorization bypass vulnerability. This flaw enables unauthenticated attackers to access sensitive student data, including course counts, points, certificates, and quiz and assignment totals of registered users. Wi...
PoC for CVE-2026-81194
The MasterStudy LMS WordPress Plugin prior to version 3.7.46 suffers from an authorization bypass, which allows authenticated users, including low-permission roles such as Subscribers, to access other instructors' sales records. This occurs when an attacker supplies another user's identifier, lea...
PoC for CVE-2026-79621
The CatalogX WordPress plugin prior to version 6.1.3 does not properly sanitize or escape user-supplied content, which allows unauthenticated users to inject arbitrary data into the product enquiry notification emails sent to site administrators. This vulnerability can lead to potential spoofing ...
PoC for CVE-2026-80467
The Advanced Custom Fields: Extended plugin for WordPress prior to version 0.9.2.7 has a vulnerability that allows unauthenticated users to submit roles through front-end user forms. This critical flaw means that the plugin does not properly restrict role submissions to the predefined roles offer...
PoC for CVE-2026-81197
The MasterStudy LMS WordPress Plugin prior to version 3.7.46 has a security flaw that allows unauthorized access to a REST endpoint. This vulnerability enables unauthenticated users to view the titles and IDs of unpublished courses, including drafts, pending, and private listings. The absence of ...
PoC for CVE-2026-81196
The MasterStudy LMS WordPress Plugin prior to version 3.7.46 suffers from an insufficient access control vulnerability that allows users with instructor access to view quiz questions, including correct answers and explanations, that belong to other instructors. This vulnerability can lead to unau...
PoC for CVE-2026-81195
The MasterStudy LMS plugin for WordPress prior to version 3.7.46 exhibits a significant authorization weakness, failing to implement necessary checks before revealing sensitive data. This vulnerability allows unauthenticated attackers to access detailed course enrollment information and progress ...
PoC for CVE-2026-78151
The FormLayer plugin for WordPress prior to version 1.0.9 is susceptible to an information exposure vulnerability. It fails to implement proper authorization checks when returning form configuration details through its public submission handler. As a result, unauthenticated users can gain access ...
PoC for CVE-2026-77788
The Rank Math SEO plugin for WordPress prior to version 1.0.277 contains a vulnerability that fails to properly validate the ownership of metadata updates. This oversight allows users with the Author role or higher to overwrite arbitrary metadata for posts and users, potentially affecting even hi...
PoC for CVE-2026-77783
The Rank Math SEO plugin for WordPress prior to version 1.0.277 fails to enforce visibility checks for posts when rendering schema. This oversight allows unauthorized users to access and disclose schema information for draft, pending, private, scheduled, and password-protected posts. As a result,...
PoC for CVE-2026-77787
The Rank Math SEO plugin for WordPress prior to version 1.0.277 lacks a proper capability check during bulk metadata updates targeting taxonomy terms. This weak point enables users with the Author role and above to modify SEO metadata of taxonomy terms they should not have the ability to edit. It...
PoC for CVE-2026-77792
The RegistrationMagic plugin for WordPress, prior to version 6.0.9.9, is vulnerable to Stored Cross-Site Scripting (XSS) due to improper escaping of registration form field values. This vulnerability permits unauthenticated attackers to inject malicious scripts that execute in the browser of high...
PoC for CVE-2026-77784
The Rank Math SEO WordPress plugin prior to version 1.0.277 contains an access control vulnerability that allows users with the Author role and above to edit SEO indexing metadata for content, taxonomy terms, and user profiles that they do not own. This improper validation leads to unauthorized a...
PoC for CVE-2026-77785
The Rank Math SEO plugin for WordPress prior to version 1.0.277 fails to adequately verify user permissions when accessing certain posts. This weakness permits users with Author roles and higher to retrieve content, including the title, body, and SEO metadata, from other users' private posts, the...
PoC for CVE-2026-19704
The Comments plugin for WordPress versions before 7.6.66 is vulnerable due to improper validation of values used in database queries. This flaw enables unauthenticated users to inject SQL code, which can reveal comments they should not have access to, such as those pending moderation, marked as s...
PoC for CVE-2026-74927
The MultiVendorX WordPress plugin prior to version 5.0.15 has a significant authorization vulnerability in its REST API listings. This flaw allows unauthenticated users to access sensitive information including vendor contact details, pending payout amounts, and private administrative notes linke...
PoC for CVE-2026-77782
The Rank Math SEO WordPress plugin prior to version 1.0.277.1 lacks proper verification for password-protected posts. This oversight allows unauthorized users to access the content of such posts, resulting in unintentional exposure of sensitive information. This vulnerability creates significant ...
PoC for CVE-2026-77764
The GamiPress plugin for WordPress, prior to version 7.9.9.6, contains a flaw in its video watch-tracking functionality that fails to adequately restrict access. This weakness allows users with minimal permissions, such as Subscribers, to unjustly award gamification points, achievements, and rank...
PoC for CVE-2026-19719
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress prior to version 3.0.1 is susceptible to Stored Cross-Site Scripting (XSS). This vulnerability arises due to the plugin's failure to properly escape post titles before rendering them in inline JavaScript event handlers. As...
PoC for CVE-2026-19723
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress, prior to version 3.0.1, contains a security flaw where it fails to properly escape user input. This weakness allows attackers to execute reflected cross-site scripting (XSS) attacks by injecting malicious scripts via an i...
PoC for CVE-2026-19453
The JetBackup plugin for WordPress, specifically versions prior to 3.1.23.5, lacks adequate checks on user role and capabilities during the restore or migration process. This flaw potentially allows users with lower privileges, such as subscribers, to escalate their access to administrator levels...
PoC for CVE-2026-19116
The User Frontend Plugin for WordPress, prior to version 4.3.11, is susceptible to a vulnerability that allows authenticated users, with subscriber-level access and above, to exploit deserialization of user-supplied input when reopening a post for editing. This can result in PHP Object Injection,...
PoC for CVE-2026-19251
The Ultimate Member plugin for WordPress prior to version 2.13.0 has a security flaw that allows unauthenticated users to access and view comments that are still awaiting moderation. This occurs because the plugin fails to verify whether a comment has been approved or whether the associated profi...
PoC for CVE-2026-16983
The Gutentor WordPress plugin prior to version 4.0.6 contains an improper access control flaw affecting its REST API endpoints. This vulnerability enables authenticated users with the Subscriber role to access plaintext passwords of password-protected posts, potentially compromising sensitive inf...
PoC for CVE-2026-16966
The Solace Extra WordPress plugin prior to version 1.7.0 is vulnerable to an authorization bypass in one of its AJAX actions. This flaw allows unauthenticated users to gain access to the contents of non-published components—such as drafts, pending posts, private entries, and trashed items—that wo...
PoC for CVE-2026-15232
The MotoPress Appointment Booking WordPress plugin suffers from an improper access control vulnerability that allows unauthenticated attackers to delete other users' reservations. This issue arises due to a lack of necessary authorization checks when processing user-supplied booking identifiers t...
PoC for CVE-2025-15664
The Ultimate Before After Image Slider & Gallery for WordPress lacks proper escaping of the slider's before-label value. This insufficiency allows users with Author roles and above to inject malicious payloads, which then execute in the browsers of users who view the slider, including administrat...
PoC for CVE-2026-12526
The Advanced Custom Fields: Extended plugin prior to version 0.9.2.7 is susceptible to an authorization bypass vulnerability. This flaw allows unauthenticated users to exploit front-end forms, enabling them to tamper with user accounts, specifically targeting administrators. By manipulating the f...
PoC for CVE-2026-14215
The Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.9 has a security flaw that permits unauthenticated users to execute the post-booking action chain without proper validation. This lapse allows malicious individuals to trigger booking notifications and exec...
PoC for CVE-2026-12865
The Photo Gallery by 10Web plugin for WordPress fails to adequately escape certain request parameters on its admin pages, specifically on the Shortcode and Galleries/Albums list pages. This oversight allows an unauthenticated attacker to craft a malicious link. When this link is accessed by a log...
PoC for CVE-2025-15663
The Ultimate Before After Image Slider & Gallery plugin for WordPress, prior to version 4.7.19, contains a vulnerability where the plugin fails to appropriately escape the slider's after-label value during the re-injection into the DOM. This flaw can be exploited by users with Author roles and ab...
Discovered 10 hours ago
PoC for CVE-2025-62593
Ray AI Compute Engine, widely utilized as a development tool, contains a significant RCE vulnerability in versions prior to 2.52.0. This vulnerability arises from a failure to properly safeguard against browser-based attacks. The existing defense mechanism inadequately relies on the User-Agent he...
PoC for CVE-2026-13753
A missing authorization vulnerability has been identified in the embedded webserver of HP Deskjet 2800 Series Printers. This issue allows an unauthenticated attacker with network access to exploit multiple exposed administrative API endpoints, potentially revealing sensitive configuration data. I...
Discovered 11 hours ago
PoC for CVE-2026-84442
A vulnerability has been discovered in the MapQuest Get Directions App version 10.16.1 for Android, specifically within the function getDataColumn located in the ExpoShareIntentModule.kt file of the component com.mapquest.android.ace. This flaw enables unauthorized access through path traversal t...
PoC for CVE-2026-84441
A vulnerability exists in the Piwigo Image Derivative Handler affecting versions up to 16.3.0, allowing attackers to exploit the i.php file through a path traversal attack. This security flaw could enable unauthorized access to system files, potentially leading to the disclosure of sensitive info...
Discovered 12 hours ago
PoC for CVE-2026-84438
A cross site scripting (XSS) vulnerability has been identified in OpenCart versions 4.1.0.3 and 4.1.0.4, which is related to an unspecified function within the Autocomplete Workflow component. This vulnerability allows attackers to manipulate the 'firstname' argument in the file catalog/controlle...
PoC for CVE-2026-84437
A flaw has been identified in OpenCart's Autocomplete Workflow, specifically within the address.php file located in the catalog/controller/account directory. This vulnerability allows attackers to craft malicious inputs that, when processed by the affected function, could execute arbitrary JavaSc...
PoC for CVE-2026-84431
A path traversal vulnerability exists in the AirAsia MOVE App for Android, specifically in the function com.airasia.core.utils.RealPathUtil.getRealPath. This issue arises from improper handling of the argument _display_name, which can be manipulated by an attacker to access sensitive files outsid...
Discovered 13 hours ago
PoC for CVE-2026-84430
A security vulnerability exists in Gouguoa versions up to 5.10.0 and 6.0.1, specifically within the update function in app/home/controller/Index.php of the edit_personal endpoint. This flaw allows an attacker to manipulate the position_id argument, leading to the potential for dynamically-determi...
PoC for CVE-2026-82221
An unauthenticated Cross Site Scripting (XSS) vulnerability exists in the RegistrationMagic plugin for WordPress, affecting versions up to and including 6.0.9.8. This vulnerability allows attackers to inject malicious scripts into the web pages viewed by users, potentially leading to data theft, ...