Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered just now...

PoC for CVE-2026-41710

SpringSpring Retry5.9MEDIUM
Stateful Retry Cache Exhaustion in Spring Retry by Pivotal Software

The vulnerability in Spring Retry allows an attacker to send numerous unique requests that overwhelm the application’s stateful retry cache. Once this cache reaches its limit, it prevents any further updates, leading to a failure in all subsequent stateful retries and circuit breaker operations. ...

PoC for CVE-2026-20685

ApplePrivate Cloud Compute ...6.5MEDIUM
Path Handling Vulnerability in Apple Private Cloud Compute

A path handling issue in Apple Private Cloud Compute may allow attackers positioned within a privileged network to exploit the vulnerability and leak sensitive information. This potential security weakness has been addressed with improved validation in PCC Release 5E290.3, enhancing the overall p...

PoC for CVE-2026-64564

LinuxLinux9.8CRITICAL
Vulnerability in Linux Kernel's SCTP Handling Can Lead to Memory Is...

A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) handling arises when processing Address Configuration (ASCONF) chunks. Specifically, the system allows for a potential memory corruption scenario by failing to protect the transport cached in the ASCONF structure. A...

PoC for CVE-2020-23349

WeiboAndroid Software Devel...7.5HIGH
Intent Redirection Vulnerability in Sina Weibo Android SDK

A vulnerability exists in the Sina Weibo Android SDK 4.2.7 where an intent redirection issue allows unexported Activities to be launched unexpectedly by the WbShareTransActivity. This could lead to unauthorized access and potential compromise of application security, making it crucial for develop...

PoC for CVE-2024-29943

MozillaFirefox🟣 EPSS 23%9.8CRITICAL
Out-of-bounds Read/Write Vulnerability Affects Firefox

The vulnerability CVE-2024-29943 affects Firefox, allowing attackers to perform an out-of-bounds read or write on a JavaScript object, enabling remote code execution and sandbox escape. The flaw was exploited during the Pwn2Own Vancouver 2024 hacking competition and affected Firefox versions befo...

Discovered 4 hours ago

PoC for CVE-2026-19089

WordPressProduct Input Fields F...
File Upload Vulnerability in WooCommerce WordPress Plugin

The WooCommerce WordPress plugin prior to version 2.0.2 is susceptible to a file upload vulnerability due to its failure to validate the types of files that can be uploaded when its accepted-types setting is left empty. This lack of validation opens the door for unauthenticated attackers to uploa...

PoC for CVE-2026-19077

WordPressDuplicate Post
Authorization Flaw in Duplicate Post Plugin Affects WordPress Sites

The Duplicate Post plugin for WordPress, prior to version 1.5.5, has a significant security flaw where it fails to enforce proper authorization checks during its bulk copy and delete functionalities. This oversight allows any user with access granted by an administrator to delete posts across the...

PoC for CVE-2026-18786

WordPressCheckview
REST API Authentication Flaw in CheckView Plugin for WordPress

The CheckView WordPress plugin contains a vulnerability that allows unauthenticated attackers to exploit the REST API due to improper handling of authentication filters. This flaw leads to the potential bypass of security mechanisms, allowing attackers to perform various actions typically reserve...

PoC for CVE-2026-19075

WordPressAll-in-one Video Gallery
Unauthenticated File Download Vulnerability in All-in-One Video Gal...

The All-in-One Video Gallery plugin for WordPress is vulnerable to an unauthenticated file download exploit. This occurs through a public file-download handler that can be triggered by accessing a specific URL pattern (`?vdl=<post_id>`). When this endpoint is accessed, it allows any user to initi...

PoC for CVE-2026-19074

WordPressAdvanced Classifieds &...
Sensitive Information Exposure in Advanced Classifieds & Directory ...

The Advanced Classifieds & Directory Pro plugin for WordPress prior to version 3.4.3 is susceptible to an unauthenticated sensitive information exposure through its AJAX action `acadp_public_custom_fields_listings`. This vulnerability allows attackers to access confidential data without proper au...

PoC for CVE-2026-15047

WordPressS2member
Stored Cross-Site Scripting in s2Member Plugin for WordPress

The s2Member WordPress plugin prior to version 260805 contains a vulnerability that fails to properly escape certain shortcode attributes. This oversight allows users with contributor-level access to execute arbitrary JavaScript within an inline script context. When a post containing the affected...

PoC for CVE-2026-18200

WordPressFoodboxbooker
Improper User Account Verification in FoodBoxBooker Plugin by WordP...

The FoodBoxBooker plugin for WordPress prior to version 1.0.8 is susceptible to an improper authorization vulnerability. This flaw enables authenticated users with Subscriber-level access or higher to update profile details of any user on the system, including those with administrative privileges...

PoC for CVE-2026-17023

WordPressSalon Booking System
OAuth Vulnerability in Salon Booking System Plugin for WordPress

The Salon Booking System WordPress plugin, up to version 10.30.33, is vulnerable to unauthorized access due to a lack of capability checks and OAuth state value validation during its Google Calendar authorization callback. This issue allows unauthenticated attackers to overwrite existing Google C...

PoC for CVE-2026-14293

WordPressAutopay
Cross-Site Scripting Vulnerability in Autopay WordPress Plugin

The Autopay WordPress plugin prior to version 5.0.1 is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw arises from the failure to validate user capabilities and nonces during the processing of styling options submitted through public requests. As a result, unauthenticated att...

PoC for CVE-2026-14237

WordPressVitepos
Authorization Flaw in Vitepos WordPress Plugin Allows Unauthorized ...

The Vitepos WordPress plugin, including versions prior to 3.6.0 and 3.5.0, is vulnerable due to the lack of a per-target authorization check in its password-reset API. This oversight grants the custom Outlet Manager role excessive permissions, enabling them to reset any user's password—including ...

PoC for CVE-2026-14211

WordPressBooking For Appointmen...
Unauthorized Data Access in Booking for Appointments and Events Cal...

The Booking for Appointments and Events Calendar WordPress plugin prior to version 9.7 contains a security flaw that allows authenticated employees to access and manipulate customer records without proper verification. This oversight permits any logged-in employee with access to the Employee Pane...

PoC for CVE-2026-14238

WordPressVitepos
SQL Injection Vulnerability in Vitepos WordPress Plugin

The Vitepos WordPress plugin, prior to version 3.6.0, suffers from a significant security flaw due to inadequate sanitization and parameterization of an identifier sourced from a REST request body. This shortcoming can be exploited by users with administrator-level access, enabling them to execut...

PoC for CVE-2026-19049

WordPressProsolution WP Client
SQL Injection Vulnerability in ProSolution WP Client Plugin by Word...

The ProSolution WP Client plugin for WordPress contains a significant vulnerability where the application fails to sanitize cookie values before utilizing them in SQL queries. This security flaw allows unauthorized users to access sensitive database information and delete records without any form...

PoC for CVE-2026-17021

WordPressSalon Booking System
Access Control Flaw in Salon Booking System Plugin for WordPress

The Salon Booking System plugin for WordPress versions up to 10.30.33 contains an access control vulnerability that lets unauthorized users manipulate AJAX actions related to booking modifications. This flaw does not adequately validate booking ownership, enabling attackers to alter the total of ...

PoC for CVE-2026-17020

WordPressSalon Booking System
Vulnerability in Salon Booking System Plugin for WordPress Allows D...

The Salon Booking System plugin for WordPress, up to version 10.30.33, has a serious vulnerability where it fails to verify the ownership of booking requests via its REST API endpoints. This flaw allows any authenticated user, including those with minimal permissions such as Subscribers or self-r...

PoC for CVE-2026-17022

WordPressSalon Booking System
Booking Data Exposure in Salon Booking System from WordPress Plugin

The Salon Booking System WordPress plugin, up to version 10.30.33, suffers from a vulnerability due to its inadequate validation of booking ownership tokens. This flaw allows unauthenticated attackers to access and disclose sensitive booking records of other customers by submitting a sequential b...

PoC for CVE-2026-15229

WordPressPinpoint Booking System
Server-Side Validation Flaw in Pinpoint Booking System Plugin for W...

The Pinpoint Booking System plugin for WordPress, up to version 2.9.9.6.9, suffers from a critical server-side validation flaw. This vulnerability enables unauthenticated users to manipulate booking prices by bypassing proper validation, potentially creating reservations for arbitrary amounts, in...

PoC for CVE-2026-19053

WordPressProsolution WP Client
SQL Injection Vulnerability in ProSolution WP Client Plugin by Word...

The ProSolution WP Client plugin for WordPress, prior to version 2.0.6, is vulnerable due to inadequate sanitization and escaping of a parameter in SQL statements. This flaw, which is accessible to unauthenticated users, allows for blind SQL injection attacks, potentially compromising the integri...

PoC for CVE-2026-18946

WordPressContact Form To Any Api
File Upload Vulnerability in Contact Form to Any API Plugin by Word...

The Contact Form to Any API plugin for WordPress prior to version 3.0.7 has a security flaw that results from not generating random filenames when files are uploaded via contact forms. This oversight allows unauthorized users to list and download files submitted by others, which could lead to dat...

PoC for CVE-2026-18960

WordPressBlock User Account
WordPress Plugin Vulnerability in Block User Account

The Block User Account plugin for WordPress, prior to version 2.0.1, fails to enforce block restrictions effectively across all authentication pathways. This shortcoming permits users who have previously set application passwords to bypass account blocks, thereby retaining access to their assigne...

PoC for CVE-2026-16985

WordPressSqueeze
File Upload Vulnerability in Squeeze WordPress Plugin by Squeeze

The Squeeze WordPress plugin prior to version 1.7.12 contains a security flaw due to its failure to validate the file type or extension of image data during attachment updates. This critical lapse allows users with the upload_files capability, such as those with Author roles or higher, to potenti...

PoC for CVE-2026-18934

WordPressRss Aggregator By Feedzy
Unauthorized Actions in RSS Aggregator Plugin for WordPress by Feedzy

The RSS Aggregator plugin by Feedzy allows users with author-level access and above to perform unauthorized actions on import jobs. This includes the ability to permanently delete posts from another user's import job and modify its settings without proper verification. Additionally, the plugin la...

PoC for CVE-2026-14941

WordPressCustomer Reviews For W...
AJAX Action Misconfiguration in Customer Reviews for WooCommerce Pl...

The Customer Reviews for WooCommerce plugin prior to version 5.116.0 contains a significant security flaw where it fails to implement necessary nonce and capability checks on multiple AJAX actions. This oversight allows users with limited permissions, such as Subscribers, to execute administrativ...

PoC for CVE-2026-14860

WordPressPodcast Player
Server-Side Request Forgery in Podcast Player for WordPress

The Podcast Player WordPress plugin prior to version 8.3.1 is susceptible to server-side request forgery (SSRF) due to inadequate validation of user-supplied input. This flaw allows an unauthenticated attacker to manipulate server requests, enabling them to target arbitrary hosts and harvest resp...

PoC for CVE-2026-14206

WordPressHt Contact Form
Data Exposure Vulnerability in HT Contact Form Plugin by WordPress

The HT Contact Form plugin for WordPress fails to implement authorization checks on its endpoint that retrieves saved form drafts. This oversight permits any unauthenticated user to access sensitive information, such as names, email addresses, phone numbers, and physical addresses stored in these...

PoC for CVE-2026-16949

WordPressTerm Pages
SQL Injection Vulnerability in Term Pages Plugin for WordPress

The Term Pages plugin for WordPress is susceptible to SQL injection due to inadequate sanitization and escaping of parameters before they are passed into SQL queries. This vulnerability enables unauthenticated attackers to exploit the flaw, potentially leading to unauthorized access and manipulat...

PoC for CVE-2026-15238

WordPressMotopress Hotel Booking
Improper Record Verification in MotoPress Hotel Booking Plugin by M...

The MotoPress Hotel Booking WordPress plugin prior to version 6.2.3 features a serious flaw where it fails to ensure proper ownership of customer records during updates. This vulnerability permits any authenticated user with a low-privilege account, such as a Subscriber, to alter or overwrite the...

PoC for CVE-2026-15237

WordPressMotopress Hotel Booking
Authorization Bypass in MotoPress Hotel Booking WordPress Plugin

The MotoPress Hotel Booking WordPress plugin, prior to version 6.2.3, is susceptible to an authorization bypass vulnerability. This flaw allows unauthenticated users to exploit a vulnerable REST endpoint to create payment records for arbitrary bookings without proper checks. As a result, maliciou...

PoC for CVE-2026-13600

WordPressAutonettv Relay
Authentication Bypass in AutoNetTV Relay Plugin for WordPress

The AutoNetTV Relay plugin for WordPress, prior to version 3.0.14, contains a significant security flaw that allows unauthenticated attackers to retrieve an administrator's session cookie during scheduled content-synchronization tasks. This occurs because the plugin fails to implement necessary c...

PoC for CVE-2026-12971

WordPressLearnpress
Server-Side Request Forgery in LearnPress WordPress Plugin Affects ...

The LearnPress WordPress plugin versions before 4.4.4 contains a flaw where it fails to properly validate user-supplied URLs before the server fetches them. This oversight allows users with the instructor role to manipulate the server into making requests to arbitrary external hosts, resulting in...

PoC for CVE-2026-13170

WordPressEventin
Local File Inclusion Vulnerability in Eventin Plugin for WordPress

The Eventin WordPress plugin, prior to version 4.1.20, is vulnerable to a local file inclusion issue due to inadequate validation of template path settings. This flaw allows users with editor-level access or higher to include and execute arbitrary local PHP files on the server. Consequently, atta...

PoC for CVE-2026-13701

WordPressAdvanced Excerpt
Stored Cross-Site Scripting in Advanced Excerpt WordPress Plugin

The Advanced Excerpt plugin for WordPress, prior to version 4.5, contains a vulnerability that fails to properly sanitize and escape a specific setting before rendering it on the front end. This oversight can potentially allow administrators, including those without the unfiltered_html capability...

PoC for CVE-2026-17018

WordPressCubeWP Framework
Authorization Flaw in CubeWP Framework Plugin for WordPress

The CubeWP Framework for WordPress, up to version 1.1.30, has a significant vulnerability that lacks proper authorization checks for reading object metadata via one of its REST API endpoints. This oversight allows users with the Contributor role and above to access and read arbitrary metadata ass...

PoC for CVE-2026-17010

WordPressSaitama Addon Pack
Stored Cross-Site Scripting Vulnerability in Saitama Addon Pack for...

The Saitama Addon Pack for WordPress versions up to 1.0.8 is prone to a stored Cross-Site Scripting (XSS) vulnerability. This flaw arises from the plugin's failure to properly sanitize and escape specific post metadata values before rendering them in the browser. As a result, users with contribut...

PoC for CVE-2026-17016

WordPressAccept Paypal & Stripe...
Payment Processing Flaw in PayPal Integration for WooCommerce by Wo...

The Accept PayPal & Stripe with Subscriptions for WooCommerce plugin for WordPress fails to properly validate the payment amount against the total order value during the PayPal Data Transfer return process. This oversight permits customers to complete transactions by paying an amount less than th...

PoC for CVE-2026-18666

WordPressLibrary Management System
SQL Injection Vulnerability in Library Management System Plugin by ...

The Library Management System plugin for WordPress prior to version 3.6.7 is susceptible to SQL injection attacks due to insufficient validation and sanitization of user-supplied inputs. This flaw allows users with minimal privileges, such as Subscribers, to manipulate SQL queries and potentially...

PoC for CVE-2026-17012

WordPressAccept Paypal & Stripe...
Payment Processing Flaw in WooCommerce Plugin by WordPress

The Accept PayPal & Stripe with Subscriptions for WooCommerce plugin, prior to version 3.1.0, suffers from a critical flaw that allows unauthenticated users to manipulate payment processes. This vulnerability occurs when the plugin fails to verify that the PayPal account receiving payment is the ...

PoC for CVE-2026-18469

WordPressLogin & Register Forms
Password Reset Bypass Vulnerability in Login & Register Forms for W...

The Login & Register Forms plugin for WordPress prior to version 4.0.2 is susceptible to a password reset bypass vulnerability. This occurs due to the failure of the plugin to properly regulate the number of password reset attempts based on a secure, server-side value. Instead, it relies on clien...

PoC for CVE-2026-18470

WordPressLogin & Register Forms
Authentication Flaw in Login & Register Forms Plugin Affects WordPr...

The Login & Register Forms plugin for WordPress versions prior to 4.0.2 contains a significant security flaw that fails to confirm if a password reset request is initiated by the authorized account owner. This oversight permits unauthorized individuals to gain access to the email addresses of reg...

PoC for CVE-2026-18468

WordPressLogin & Register Forms
Account Takeover Vulnerability in Login & Register Forms Plugin by ...

The Login & Register Forms plugin for WordPress before version 4.0.2 is susceptible to an account takeover vulnerability. This occurs when the password reset verification state is improperly managed, allowing unauthenticated attackers to exploit the vulnerability and gain unauthorized access to u...

PoC for CVE-2026-18030

WordPressBricksforge
Authorization Bypass in BricksForge WordPress Plugin Affects User A...

The BricksForge WordPress plugin, versions prior to 3.1.8.8, is vulnerable to an unauthorized password change due to insufficient verification of the requester's identity. This flaw enables unauthenticated attackers to manipulate password reset actions, potentially gaining control over user accou...

PoC for CVE-2026-16257

WordPressArvow Ai Seo Writer
Access Control Vulnerability in Arvow AI SEO Writer WordPress Plugin

The Arvow AI SEO Writer WordPress plugin prior to version 1.5.4 contains an access control vulnerability that permits unauthenticated users to exploit a REST endpoint. This flaw arises from inadequate access restrictions, specifically allowing adversaries to bypass security measures via type jugg...

PoC for CVE-2026-17019

WordPressJetengine
Stored Cross-Site Scripting Vulnerability in JetEngine WordPress Pl...

The JetEngine plugin for WordPress prior to version 3.8.13.1 is vulnerable due to inadequate sanitization of uploaded SVG files. This flaw permits unauthorized users to upload files containing harmful JavaScript, which executes in the browsers of users viewing the affected site. As a result, the ...

PoC for CVE-2026-16299

WordPressSingle Sign On For Tng
Password Reset Vulnerability in Single Sign On For TNG WordPress Pl...

The Single Sign On For TNG WordPress plugin prior to version 2.2.0 has a vulnerability that fails to properly validate password reset requests. This flaw allows an unauthenticated attacker to reset passwords of any user, including administrators, potentially enabling a full site takeover. Adminis...

PoC for CVE-2026-16298

WordPressFoodboxbooker
Password Reset Vulnerability in FoodBoxBooker Plugin for WordPress

The FoodBoxBooker WordPress plugin versions prior to 1.0.7 contain a vulnerability that fails to adequately validate password reset requests. This weakness permits unauthenticated attackers to modify the passwords of any user, including those with administrative rights. Such an exploit could lead...