Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2025-31207

AppleiOS And iPad OS7.7HIGH
Logic Issue in iOS and iPadOS Allows App Enumeration

A logic issue in iOS and iPadOS may allow a malicious app to enumerate the installed applications on a user's device. This could lead to potential privacy breaches, where sensitive information about user preferences and installations could be exposed. The issue has been addressed with enhanced ch...

PoC for CVE-2018-9995

TbkvisionTbk-dvr4216 Firmware🟣 EPSS 83%9.8CRITICAL
Authentication Bypass Vulnerability in TBK and Rebranded DVR Devices

Certain DVR devices, including the TBK DVR4104 and DVR4216 models, as well as various rebranded variants, are susceptible to a remote authentication bypass. By manipulating the 'Cookie: uid=admin' header, attackers can access sensitive functionalities without proper authentication. This vulnerabi...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 57 minutes ago

PoC for CVE-2025-10897

WordPressWooCommerce Designer Pro8.6HIGH
Arbitrary File Read Vulnerability in WooCommerce Designer Pro Theme...

The WooCommerce Designer Pro theme for WordPress is vulnerable to an arbitrary file read, impacting all versions up to and including 1.9.28. This vulnerability allows unauthenticated attackers to read sensitive files from the server, potentially exposing critical information such as database cred...

Discovered 1 hour ago

PoC for CVE-2026-15236

WordPressGallery For Google Photos
Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth To...

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.

PoC for CVE-2026-16540

WordPressSimply Schedule Appoin...
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointme...

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently dele...

PoC for CVE-2025-15675

WordPressCharitable
Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting attacks that execute on the front-end ...

PoC for CVE-2026-13389

WordPressWebtoffee-cookie-consent
WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion,...

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before...

PoC for CVE-2026-16062

WordPressEvent Booking Manager ...
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Ob...

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Ma...

PoC for CVE-2026-16285

WordPressProduct Attachment For...
WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary ...

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.

PoC for CVE-2026-16063

WordPressEvent Booking Manager ...
Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS ...

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary Ja...

PoC for CVE-2026-16292

WordPressFrontend File Manager ...
Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest ...

PoC for CVE-2026-16064

WordPressEvent Booking Manager ...
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitr...

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status ...

PoC for CVE-2026-16291

WordPressProfilegrid
ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion...

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.

PoC for CVE-2026-16273

WordPressNarrative Publisher
Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrativ...

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the ...

PoC for CVE-2026-16261

WordPressLogin-social
Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as a...

PoC for CVE-2026-16042

WordPressLws Optimize
LWS Optimize < 3.4 - Subscriber+ Cache Deletion

The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.

PoC for CVE-2026-15939

WordPressSimple Restrict
Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosur...

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing ...

PoC for CVE-2026-15385

WordPressRt Mega Menu
RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS

The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can therefore enable ...

PoC for CVE-2026-16256

WordPressPouco Import Users
Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new adm...

PoC for CVE-2026-11872

WordPressClever Mega Menu For V...
Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu It...

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered ...

PoC for CVE-2026-14817

WordPressElement Pack Addons Fo...
Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Sto...

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary Jav...

PoC for CVE-2026-12586

WordPressLenxel WP
Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrar...

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.

PoC for CVE-2026-15241

WordPressAi Chatbot For WooComm...
ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini AP...

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feat...

PoC for CVE-2026-15248

WordPressMeta Box
Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via ...

The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.

PoC for CVE-2026-15206

WordPressSms Alert
SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticat...

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and...

PoC for CVE-2026-14938

WordPressFluentboards
FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via...

The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (includin...

PoC for CVE-2026-15151

WordPressFive Star Restaurant R...
Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missi...

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's sett...

PoC for CVE-2026-14864

WordPressJetengine
JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as admin...

PoC for CVE-2026-14920

Acymailing
AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscripti...

## Summary

PoC for CVE-2026-14841

WordPressKing Addons For Elementor
King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid ...

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a...

Discovered 3 hours ago

PoC for CVE-2026-14483

WordPressRealtyna Organic Idx P...9.8CRITICAL
Arbitrary File Upload Vulnerability in Realtyna Organic IDX and WPL...

The Realtyna Organic IDX and WPL Real Estate plugins for WordPress are susceptible to arbitrary file upload due to inadequate file type validation in the upload function. This vulnerability affects all versions up to and including 5.2.0. The issue arises from a publicly accessible I/O endpoint th...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 11 hours ago

PoC for CVE-2026-12478

Red HatRed Hat Enterprise Lin...4.8MEDIUM
Integer Overflow Vulnerability in libsoup Affecting Red Hat Products

This vulnerability arises due to the improper placement of an integer overflow guard in libsoup, specifically within the conditional block for masked frames. As a result, unmasked server-to-client frames are vulnerable. A malicious WebSocket server could exploit this flaw by sending a specially c...

PoC for CVE-2023-44487

IetfHttp🟣 EPSS 100%7.5HIGH
HTTP/2 Protocol Vulnerability Allows for Rapid Stream Cancellation ...

The HTTP/2 protocol is susceptible to a denial of service vulnerability that can be exploited via rapid stream resets. This allows attackers to overwhelm servers by rapidly canceling requests, leading to significant resource consumption and potential service disruption. Exploitation of this vulne...

Discovered 14 hours ago

PoC for CVE-2026-53576

Kestra-ioKestra10CRITICAL
Authentication Bypass in Kestra Orchestration Platform by Kestra

The Kestra orchestration platform suffers from an authentication bypass vulnerability in its REST API. Specifically, any request ending with '/configs' is treated as public, bypassing necessary credential checks. This lack of authentication allows unauthorized users to create and execute flows, p...

Discovered 15 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-8239

Concrete CmsConcrete Cms6.3MEDIUM
IDOR Vulnerability in Concrete CMS by Concrete5

Concrete CMS versions 9.5.0 and earlier are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. The '/ccm/frontend/conversations/get_rating' endpoint allows unauthorized users to confirm the existence of any message's ID and retrieve its rating score. This exposes sensitive i...

Discovered 1 day ago

PoC for CVE-2026-14839

WordPressMapster WP Maps
Unauthorized Access Issue in Mapster WP Maps Plugin by WordPress

The Mapster WP Maps plugin for WordPress, prior to version 1.24.0, is susceptible to an unauthorized access vulnerability. The plugin fails to implement necessary authorization or post-status checks on a public REST endpoint. This oversight permits unauthenticated users to access sensitive data, ...

PoC for CVE-2026-14840

WordPressYop Poll
Voting Manipulation Vulnerability in YOP Poll Plugin by WordPress

The YOP Poll plugin for WordPress prior to version 7.0.6 is susceptible to a flaw that fails to properly validate the origin of connection IP addresses. This vulnerability allows unauthorized users to exploit the plugin's per-IP vote restrictions by trusting client-controlled forwarding headers. ...

PoC for CVE-2026-14823

WordPressEvent Tickets And Regi...
Authorization Bypass in Event Tickets and Registration Plugin by Wo...

The Event Tickets and Registration plugin for WordPress versions before 5.29.0.1 is susceptible to an authorization bypass issue. This flaw allows users with contributor-level access and higher privileges to manipulate seating arrangements, adjust ticket inventory, and reassign attendee seating f...

PoC for CVE-2026-14315

WordPressPixel Tag Manager For ...
Unauthorized Access Vulnerability in Pixel Tag Manager for WooComme...

The Pixel Tag Manager for WooCommerce plugin prior to version 2.2.1 is susceptible to an authorization check failure in one of its AJAX actions. This vulnerability allows unauthenticated users to exploit the system by submitting forged e-commerce conversion events. The unauthorized use can lead t...

PoC for CVE-2026-14822

WordPressEvent Tickets And Regi...
Authorization Flaw in Event Tickets and Registration Plugin for Wor...

The Event Tickets and Registration plugin for WordPress before version 5.29.0.1 features a significant security issue where it lacks authorization checks on its order-management REST endpoints. This deficiency enables unauthenticated users to manipulate the status of existing orders, potentially ...

PoC for CVE-2026-14561

WordPressAuthora : Easy Login W...
Unauthorized Access Flaw in Authora Plugin Allows Logins via Mobile...

The Authora: Easy login with mobile number WordPress plugin prior to version 1.7.7 has a serious flaw that exposes its one-time login code during unauthenticated actions. This vulnerability allows attackers to retrieve the login code along with a valid verification token, granting them unauthoriz...

PoC for CVE-2026-14292

WordPressDownload Manager
JavaScript Execution Vulnerability in Download Manager Plugin for W...

The Download Manager plugin for WordPress prior to version 3.3.66 contains a vulnerability where it fails to properly escape the titles of packages before rendering them on the frontend. This oversight allows users with the Author role or higher to inject arbitrary JavaScript into these titles. C...

PoC for CVE-2026-14214

WordPressBooking For Appointmen...
Unauthorized Field Modification in Booking for Appointments and Eve...

The Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.4 permits users with the Amelia Manager role to manipulate arbitrary fields in user records through its import feature. This vulnerability allows for unauthorized alterations, potentially compromising the i...

PoC for CVE-2026-14195

WordPressBrizy
Authorization Bypass in Brizy WordPress Plugin Affects User Privacy

The Brizy plugin for WordPress fails to adequately verify user authorization on its request handler prior to content retrieval. This oversight permits users with a Contributor role or higher to access and read the content of arbitrary posts. Consequently, users can potentially view other users' p...

PoC for CVE-2026-13725

WordPressDynamic Pricing With D...
Reflected XSS Vulnerability in Dynamic Pricing With Discount Rules ...

The Dynamic Pricing With Discount Rules for WooCommerce plugin, prior to version 5.0.0, fails to validate nonces and user capabilities during certain AJAX requests. This weakness allows attackers to inject unsanitized input, potentially leading to reflected cross-site scripting (XSS) attacks. If ...

PoC for CVE-2026-13729

WordPressPodlove Podcast Publisher
CSRF Vulnerability in Podlove Podcast Publisher Plugin by WordPress

The Podlove Podcast Publisher WordPress plugin fails to implement nonce validation for various administrative create and delete actions. This oversight opens the door for potential attackers to execute unauthorized actions, such as creating rogue records or deleting legitimate ones. Such exploits...

PoC for CVE-2026-13604

WordPressPixelavo
Unauthorized Event Injection in Pixelavo WordPress Plugin

The Pixelavo WordPress plugin prior to version 1.5.4 exposes an unauthenticated AJAX action that relies solely on a publicly available nonce. This security gap permits malicious users to send unauthorized event data to the Facebook Conversions API, leveraging the administrator's access token. Con...