Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 39 minutes ago

PoC for CVE-2026-87902

WordPressWordPress8.1HIGH
Local File Inclusion in WordPress Leading to Remote Code Execution

An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...

Discovered 2 hours ago

PoC for CVE-2026-96552

SfturingHosp Order2.3LOW
One-Way Hash Vulnerability in sfturing User Password Handler

A vulnerability exists within the sfturing hosp_order that involves the User Password Handler, specifically in the MD5.getMD5 function of the MD5.java file. This vulnerability allows for the creation of a one-way hash without the inclusion of a salt, which can expose user passwords to potential a...

PoC for CVE-2026-96551

SfturingHosp Order5.3MEDIUM
Cross-Site Request Forgery in Sfturing Hosp_Order Products

A cross-site request forgery vulnerability exists in the Sfturing Hosp_Order system, specifically within the CommonUserController.java file. This flaw allows attackers to execute unauthorized commands on behalf of authenticated users from a remote location. As there is no versioning for the affec...

PoC for CVE-2026-94127

F5Big-ip9.3CRITICAL
Remote Code Execution Vulnerability in F5 BIG-IP APM

A significant vulnerability exists in F5 BIG-IP APM when specific configurations involving OAuth profiles are applied to a virtual server. This issue can potentially allow an unauthenticated attacker to execute arbitrary code remotely, which poses a serious risk to system integrity and security. ...

PoC for CVE-2026-96550

SfturingHosp Order6.3MEDIUM
Cleartext Transmission Vulnerability in Sfturing Hosp_Order Product

A vulnerability found in the Sfturing Hosp_Order product affects the getProperties function within the MailUtil.java file. This vulnerability leads to the cleartext transmission of sensitive information, which can be exploited remotely. The complexity of successfully executing an attack is high, ...

Discovered 3 hours ago

PoC for CVE-2026-96549

SfturingHosp Order4.8MEDIUM
Cleartext Storage Vulnerability in sfturing hosp_order Software

A vulnerability discovered in the sfturing hosp_order software permits the cleartext storage of sensitive information, exposing critical data to unauthorized local access. This flaw resides within the CommonUserServiceImpl.java file and can be exploited only from a local environment. The vulnerab...

PoC for CVE-2026-96548

SfturingHosp Order6.3MEDIUM
Hard-Coded Credential Vulnerability in sfturing hosp_order by sfturing

A serious flaw in the sfturing hosp_order application allows for the use of hard-coded credentials, which poses significant security risks. This vulnerability affects a specific part of the application's configuration in the jdbc.properties file, making it exploitable through remote means. The la...

Discovered 4 hours ago

PoC for CVE-2026-1769

XeroxCentreware5.3MEDIUM
Cross-Site Scripting Vulnerability in Xerox CentreWare Software

This vulnerability enables stored cross-site scripting (XSS) attacks in Xerox CentreWare, allowing malicious users to inject and execute harmful scripts on the web interface. It affects versions of CentreWare up to 7.0.6 and can compromise the security of users accessing the platform. For improve...

Discovered 5 hours ago

PoC for CVE-2026-93349

FrictionlessdataFrictionless-py8.6HIGH
OS Command Injection Vulnerability in Frictionless Data Package by ...

The Frictionless Data Package through version 5.20.0rc1 contains a vulnerability that allows remote attackers to execute arbitrary operating system commands. This exploitation occurs through the 'explore' console command when a user interacts with a crafted Data Package descriptor. Attackers can ...

Discovered 7 hours ago

PoC for CVE-2026-87902

WordPressWordPress8.1HIGH
Local File Inclusion in WordPress Leading to Remote Code Execution

An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...

Discovered 9 hours ago

PoC for CVE-2019-11707

MozillaFirefox Esr🟣 EPSS 38%8.8HIGH
Type Confusion Vulnerability in Mozilla Firefox and Thunderbird

A type confusion vulnerability exists in Mozilla Firefox and Thunderbird, stemming from improper handling of JavaScript objects in the Array.pop function. This flaw can facilitate an exploitable crash, potentially compromising the stability and security of affected applications. Recent attacks in...

PoC for CVE-2026-84091

WordPressSumit Payment Gateway ...5.3MEDIUM
Unauthorized Payment Processing in SUMIT Payment Gateway for WooCom...

The SUMIT Payment Gateway for WooCommerce for WordPress prior to version 4.0.0 is susceptible to a security flaw that allows unauthorized marking of pending orders as paid. This occurs because the plugin fails to authenticate payment notifications from the payment provider, enabling unauthenticat...

Discovered 10 hours ago

PoC for CVE-2026-87902

WordPressWordPress8.1HIGH
Local File Inclusion in WordPress Leading to Remote Code Execution

An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...

Discovered 11 hours ago

PoC for CVE-2026-90898

MaximhqBifrost9.8CRITICAL
Unauthenticated MCP Client Registration in Bifrost by Maximhq

The vulnerability in Bifrost allows malicious users to register an MCP client through the management API without authentication. By exploiting this flaw, an attacker can issue an unauthenticated POST request to the /api/mcp/client endpoint, allowing them to execute commands as the Bifrost process...

PoC for CVE-2026-90950

WordPressPaid Membership Subscr...5.3MEDIUM
Verification Bypass in Paid Membership Subscriptions Plugin for Wor...

The Paid Membership Subscriptions plugin for WordPress, prior to version 3.1.0, has a significant vulnerability related to the reCAPTCHA verification process. When the registration handler experiences a missing form field in the request, it fails to properly verify the reCAPTCHA. This oversight a...

PoC for CVE-2026-87978

WordPressPaymob For WooCommerce5.3MEDIUM
Webhook Signature Bypass in Paymob for WooCommerce Plugin

The Paymob for WooCommerce WordPress plugin before version 4.1.14 suffers from a webhook signature verification flaw. This vulnerability enables unauthenticated attackers to exploit the payment processing feature, allowing them to falsely mark WooCommerce orders as paid, potentially resulting in ...

PoC for CVE-2026-87848

WordPressMpcx Lightbox3.7LOW
Unauthenticated Access Vulnerability in MPCX Lightbox Plugin for Wo...

The MPCX Lightbox plugin for WordPress, versions 1.2.2 to 1.2.5, is vulnerable due to a lack of authorization on one of its AJAX actions, which is accessible to unauthenticated users. This allows unauthorized visitors to access sensitive information, including titles, content, excerpts, and other...

PoC for CVE-2026-87070

WordPressForminator Forms5.3MEDIUM
Improper Handling of Forwarding Headers in Forminator Forms Plugin

The Forminator Forms plugin for WordPress prior to version 1.57.2.1 fails to validate that requests originate from a trusted proxy, leading to a situation where client-supplied forwarding headers are prioritized over the connecting IP address. This vulnerability allows unauthenticated users to by...

PoC for CVE-2026-87071

WordPressForminator Forms5.3MEDIUM
Form Submission Metadata Injection in Forminator Forms Plugin by WP...

The Forminator Forms plugin for WordPress prior to version 1.57.2.1 is susceptible to a vulnerability that allows unauthenticated users to submit arbitrary metadata while filling out public forms. This flaw allows attackers to attach unauthorized metadata keys to form submissions, including those...

PoC for CVE-2026-86612

WordPressNinja Tables5.6MEDIUM
Shortcode Execution Vulnerability in Ninja Tables by WPDeveloper

The Ninja Tables plugin for WordPress, prior to version 5.2.17, suffers from an improper access control vulnerability that allows unauthorized users to execute arbitrary shortcodes on public pages. This issue arises when the plugin fails to restrict shortcode functioning to only administrator-aut...

PoC for CVE-2026-86601

WordPressWP Recipe Maker6.5MEDIUM
Arbitrary Shortcode Execution in WP Recipe Maker Plugin by WordPress

The WP Recipe Maker plugin for WordPress prior to version 10.8.2 is susceptible to a security flaw where it fails to sanitize shortcodes in comment content. As a result, unauthenticated users can exploit this oversight, leading to the execution of arbitrary shortcodes on the server side. This vul...

PoC for CVE-2026-86604

WordPressGtranslate4.8MEDIUM
Arbitrary Code Execution in GTranslate Plugin for WordPress

The GTranslate plugin for WordPress versions prior to 5.0.1 contains a vulnerability that permits unauthenticated users to execute arbitrary shortcodes on the server side through outgoing emails. This occurs as the plugin fails to adequately sanitize shortcodes from email content when sent, parti...

Discovered 16 hours ago

PoC for CVE-2026-91077

WordPressEvent Booking Manager ...2.7LOW
Authorization Flaw in Event Booking Manager for WooCommerce Plugin ...

The Event Booking Manager for WooCommerce plugin for WordPress prior to version 5.7.3 is susceptible to an authorization flaw. This vulnerability allows users with contributor-level access and above to bypass restrictions and access private, draft, or trashed events that they should not be permit...

PoC for CVE-2026-93508

WordPressWc Fields Factory8.1HIGH
Access Control Vulnerability in WC Fields Factory WordPress Plugin

The WC Fields Factory plugin for WordPress prior to version 4.1.11 suffers from an improper access control vulnerability. This flaw allows authenticated users with Subscriber-level roles and higher to exploit the field-management AJAX action. As a result, these users can create, modify, or delete...

PoC for CVE-2026-93528

WordPressNp Quote Request For W...3.7LOW
Order Detail Exposure in NP Quote Request for WooCommerce Plugin by...

The NP Quote Request for WooCommerce plugin prior to version 2.4.16 lacks proper validation of order ownership, enabling unauthorized users to access and view another customer's order details merely by obtaining the order key. This oversight poses a significant threat to customer privacy and coul...

PoC for CVE-2026-93511

WordPressPremium Packages5.3MEDIUM
Unverified Payment Processing Vulnerability in Premium Packages Plu...

The Premium Packages plugin for WordPress prior to version 7.2.1 contains a flaw that fails to verify PayPal's webhook signature before processing payment and subscription notifications. This vulnerability allows attackers to impersonate legitimate payment confirmations and subscription cancellat...

PoC for CVE-2026-93507

WordPressWc Fields Factory3.3LOW
Access Control Vulnerability in WC Fields Factory WordPress Plugin

The WC Fields Factory plugin for WordPress prior to version 4.1.11 contains a flaw that allows contributors and higher-level users to bypass restrictions on post cloning. The plugin lacks adequate nonce verification for the cloning action, enabling unauthorized users to duplicate any posts, inclu...

PoC for CVE-2026-93510

WordPressPoints And Rewards For...4.3MEDIUM
Improper Input Validation in Points and Rewards for WooCommerce by ...

The Points and Rewards for WooCommerce plugin for WordPress prior to version 2.10.4 contains a significant vulnerability that allows authenticated users, including those with Subscriber privileges or higher, to manipulate reward claims. It lacks necessary validation mechanisms to ensure that rewa...

PoC for CVE-2026-90985

WordPressWPc Smart Compare For ...5.3MEDIUM
Post-Password Protection Bypass in WPC Smart Compare for WooCommerc...

The WPC Smart Compare for WooCommerce plugin, prior to version 6.6.1, fails to enforce WordPress's post-password protection when displaying product content. As a result, unauthenticated users can access the descriptions of products that should be restricted, leading to potential exposure of sensi...

PoC for CVE-2026-91073

WordPressSubscribe Forms6.8MEDIUM
Stored Cross-Site Scripting in Subscribe Forms Plugin for WordPress

The Subscribe Forms WordPress plugin prior to version 1.6.3 fails to properly sanitize and escape form settings before rendering them on web pages. This oversight allows authenticated users with the Author role and higher to exploit the vulnerability and perform stored cross-site scripting attack...

PoC for CVE-2026-91025

WordPressBooking Manager4.3MEDIUM
Authorization Bypass in Booking Manager Plugin by WordPress

The Booking Manager plugin for WordPress prior to version 2.1.21 contains an authorization bypass vulnerability. This flaw allows authenticated users with subscriber-level access and above to manipulate the Booking Manager's per-user settings of any user, including administrators. The plugin fail...

PoC for CVE-2026-90951

WordPressPaid Membership Subscr...3.7LOW
Unauthenticated Payment Action in Paid Membership Subscriptions Plu...

The Paid Membership Subscriptions plugin for WordPress contains a vulnerability that allows unauthenticated attackers to manipulate payment actions. Specifically, it fails to properly bind a particular unauthenticated payment processing action to the requesting user. As a result, if an attacker p...

PoC for CVE-2026-91024

WordPressBooking Manager6.8MEDIUM
SQL Injection Vulnerability in Booking Manager Plugin for WordPress

The Booking Manager plugin for WordPress prior to version 2.1.21 is susceptible to an SQL injection vulnerability. This occurs due to improper sanitization and escaping of values derived from external iCalendar feeds before they are incorporated into SQL queries. Authenticated users with Author-l...

PoC for CVE-2026-88997

WordPressJsm Show Post Metadata6.8MEDIUM
Cross-Site Scripting in JSM Show Post Metadata Plugin for WordPress

The JSM Show Post Metadata plugin for WordPress prior to version 4.9.1 is susceptible to a cross-site scripting (XSS) vulnerability. This flaw arises from the failure to properly escape post meta keys before outputting them within inline event-handler attributes in admin-facing meta boxes. As a r...

PoC for CVE-2026-88929

WordPressProduct Badge, Label, ...5.3MEDIUM
Exposed Product Information in WooCommerce Plugin by WordPress

The Product Badge, Label, Countdown Timer for WooCommerce plugin for WordPress fails to implement necessary checks to verify if a product is published before disclosing its details to unauthenticated users. This flaw allows unauthorized individuals to access and read sensitive information, such a...

PoC for CVE-2026-87979

WordPressPaymob For WooCommerce5.3MEDIUM
Payment Webhook Vulnerability in Paymob for WooCommerce by WordPress

The Paymob for WooCommerce plugin prior to version 4.1.14 has a significant security flaw that allows attackers to exploit the payment webhook by failing to verify request signatures. This enables unauthorized individuals to create card-token records associated with any user account, and potentia...

PoC for CVE-2026-87981

WordPressPaymob For WooCommerce4.7MEDIUM
Admin AJAX Actions Vulnerability in Paymob for WooCommerce WordPres...

The Paymob for WooCommerce plugin for WordPress prior to version 4.1.14 contains a significant access control flaw that lacks appropriate capability checks on multiple admin AJAX actions. This oversight enables users with contributor-level permissions to delete, modify, or erase critical payment-...

PoC for CVE-2026-89331

WordPressFluentboards5.3MEDIUM
Information Disclosure in FluentBoards WordPress Plugin by Fluent

The FluentBoards WordPress plugin prior to version 2.1.0 has a security flaw that allows unauthenticated users to access member information from public, token-shared boards. This vulnerability enables the exposure of email addresses associated with the board's members, including potentially sensi...

PoC for CVE-2026-87074

WordPressForminator Forms3.7LOW
Forminator Forms WordPress Plugin Vulnerability Exposing User Data

The Forminator Forms WordPress plugin prior to version 1.57.2.1 is vulnerable due to improper handling of saved-draft notifications. This flaw allows unauthenticated visitors to leverage the plugin's capabilities to send messages from the site using its own mail configurations without any restric...

PoC for CVE-2026-86783

WordPressPost Grid Gutenberg Bl...5.3MEDIUM
Authorization Bypass in Post Grid Gutenberg Blocks Plugin by WordPress

The Post Grid Gutenberg Blocks plugin for WordPress allows unauthenticated users to query a REST API endpoint that exposes the custom field keys of posts without sufficient authorization checks. This vulnerability can lead to the unintentional disclosure of sensitive data, including the keys of p...

PoC for CVE-2026-86608

WordPressWP Recipe Maker8.2HIGH
Unauthorized Data Manipulation in WP Recipe Maker Plugin by X Company

The WP Recipe Maker plugin for WordPress has a significant security flaw that allows unauthenticated users to perform unauthorized data manipulations. This vulnerability arises due to a lack of authentication checks in specific REST routes, enabling attackers to write unbounded data into any user...

PoC for CVE-2026-87069

WordPressForminator Forms3.1LOW
Unauthorized Access in Forminator Forms Plugin Allows Configuration...

The Forminator Forms WordPress plugin prior to version 1.57.2.1 contains a significant security flaw that allows authenticated users, including those with minimal permissions (like Subscribers), to alter the saved configurations of forms, including payment forms. This issue arises from the absenc...

PoC for CVE-2026-86842

WordPressReal3d Flipbook6.8MEDIUM
Authentication Bypass in Real3D Flipbook WordPress Plugin

The Real3D Flipbook plugin for WordPress, prior to version 5.4, lacks proper capability checks for several authenticated management actions. This oversight enables users with Author-level access or higher to delete flipbook content created by other users and modify global settings, typically rest...

PoC for CVE-2026-86602

WordPressWP Recipe Maker4.3MEDIUM
Insufficient Capability Check in WP Recipe Maker Plugin by WP Recip...

The WP Recipe Maker plugin for WordPress prior to version 10.8.2 contains a flaw in its AJAX actions, where it fails to validate user capabilities. This oversight allows any authenticated user, including those with minimal permissions, to access sensitive data, specifically the full content of un...

PoC for CVE-2026-86603

WordPressWP Recipe Maker4.3MEDIUM
Authorization Bypass in WP Recipe Maker Plugin by WordPress

The WP Recipe Maker plugin for WordPress prior to version 10.8.2 lacks proper authorization checks in specific AJAX actions. This flaw permits any authenticated user, including those with minimal permissions such as subscribers, to access the IDs and titles of unpublished lists owned by other use...

PoC for CVE-2026-85006

WordPressHappyaddons For Elementor6.8MEDIUM
Cross-Site Scripting Flaw in HappyAddons for Elementor Plugin by Wo...

The HappyAddons for Elementor plugin for WordPress before version 3.50.0 contains a security flaw that fails to properly validate an icon value within one of its button widgets. This oversight allows users with Contributor-level access and higher to inject malicious event-handler attributes. Cons...

PoC for CVE-2026-84741

WordPressThe Events Calendar5.3MEDIUM
Excessive Data Exposure in Events Calendar Plugin for WordPress

The Events Calendar plugin for WordPress, prior to version 6.17.5, exhibits a serious flaw in its handling of linked records. Specifically, the plugin fails to verify the post status of these records before including their details in responses from the public REST API. This oversight enables unau...

PoC for CVE-2026-84150

WordPressDirectorist: Ai-powere...5.4MEDIUM
REST Route Validation Flaw in Directorist Plugin for WordPress

The Directorist: AI-Powered Business Directory plugin for WordPress is susceptible to an authorization bypass vulnerability. This issue arises because the plugin fails to ensure that the user calling a REST API route is indeed the owner of the data they are trying to access. As a result, authenti...

PoC for CVE-2026-84743

WordPressThe Events Calendar3.8LOW
Improper Access Control in Events Calendar Plugin for WordPress

The Events Calendar plugin for WordPress, prior to version 6.17.5, contains an improper access control vulnerability in its REST API write routes. This flaw permits users with low-privilege roles, such as contributors, to perform actions typically reserved for higher-privileged roles, enabling th...

PoC for CVE-2026-84168

WordPressEasy Hide Login5.3MEDIUM
Authentication Bypass in Easy Hide Login Plugin for WordPress

The Easy Hide Login WordPress plugin prior to version 1.7 is vulnerable to an authentication bypass that permits unauthenticated attackers to access the standard login page. By manipulating specific password-reset request parameters, an attacker can retrieve the configured secret login slug, effe...