Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 8 hours ago

PoC for CVE-2026-82183

WordPressOauth Single Sign On8.1HIGH
OAuth Single Sign On Plugin for WordPress Exposes User Accounts

The OAuth Single Sign On plugin for WordPress suffers from a significant flaw in its handling of the Steam single sign-on process. This flaw permits unauthenticated attackers to bypass authentication mechanisms, allowing them to log in as any non-administrator user. Furthermore, the vulnerability...

PoC for CVE-2026-81583

WordPressTheme My Login5.4MEDIUM
Improper Access Control in My Login WordPress Plugin Affects Networ...

The My Login WordPress plugin prior to version 7.2.0 is susceptible to a vulnerability that fails to adhere to the network's registration settings during the sign-up process on multisite installations. This flaw permits users with subscriber accounts and even unauthenticated individuals on certai...

PoC for CVE-2026-81807

WordPressSimple Ajax Chat8.8HIGH
Cross-Site Scripting in Simple Ajax Chat Plugin by WordPress

The Simple Ajax Chat plugin for WordPress, prior to version 20260827, is susceptible to a cross-site scripting vulnerability. This issue arises because the plugin fails to properly escape chat message content before it is displayed. As a result, an unauthenticated user can inject arbitrary HTML a...

PoC for CVE-2026-82182

WordPressWPvivid — Backup, Migr...
SQL Injection Vulnerability in WPvivid Backup, Migration & Staging ...

The WPvivid Backup, Migration & Staging plugin prior to version 0.9.133 is susceptible to SQL injection due to inadequate sanitization of user-supplied identifiers in a SQL query. This vulnerability could be exploited by malicious users to execute arbitrary SQL commands, potentially compromising ...

PoC for CVE-2026-81737

WordPressFaq Builder Ays8.8HIGH
Stored XSS Vulnerability in FAQ Builder AYS WordPress Plugin

The FAQ Builder AYS WordPress plugin, prior to version 1.8.5, has a vulnerability that permits unauthenticated users to submit content without proper sanitization or escaping. This leads to the potential for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be executed in the...

PoC for CVE-2026-81426

WordPressWc Vendors4.3MEDIUM
CSRF Vulnerability in WC Vendors Plugin for WordPress

The WC Vendors plugin for WordPress, prior to version 2.7.2.1, lacks adequate protection against Cross-Site Request Forgery (CSRF) attacks on certain front-end actions related to order shipment status. This vulnerability potentially allows attackers to exploit logged-in vendor accounts to alter t...

PoC for CVE-2026-81428

WordPressWc Vendors6.5MEDIUM
Authorization Flaw in WC Vendors Plugin for WordPress

The WC Vendors plugin for WordPress, prior to version 2.7.2.1, contains a critical oversight that allows authenticated users with vendor roles to manipulate product variations that do not belong to them. By exploiting this flaw, these users can alter the status and title of various posts and prod...

PoC for CVE-2026-81427

WordPressWc Vendors4.3MEDIUM
Authorization Flaw in WC Vendors Plugin Affects WordPress Users

The WC Vendors plugin for WordPress prior to version 2.7.2.1 contains a significant authorization flaw. This security issue allows any authenticated vendor to modify the shipment status of orders they do not own. As a result, they can mark orders as shipped, which misrepresents their involvement ...

PoC for CVE-2026-81432

WordPressJetstylemanager For Gu...4.3MEDIUM
CSRF Vulnerability in JetStyleManager for Gutenberg WordPress Plugin

The JetStyleManager for Gutenberg WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) attacks. Specifically, versions prior to 1.3.9 lack adequate CSRF protection on certain AJAX actions. This weakness can be exploited by attackers who can deceive a logged-in user with the edit_po...

PoC for CVE-2026-81198

WordPressMasterstudy Lms WordPr...3.8LOW
Improper Ownership Verification in MasterStudy LMS Plugin by WordPress

The MasterStudy LMS Plugin for WordPress prior to version 3.7.46 contains a vulnerability that allows authenticated users with instructor privileges to manipulate curriculum objects. This flaw occurs due to inadequate verification of ownership, enabling these users to delete or alter course secti...

PoC for CVE-2026-81199

WordPressMasterstudy Lms WordPr...5.3MEDIUM
Unauthorized Access Vulnerability in MasterStudy LMS WordPress Plugin

The MasterStudy LMS WordPress Plugin prior to version 3.7.46 is susceptible to an authorization bypass vulnerability. This flaw enables unauthenticated attackers to access sensitive student data, including course counts, points, certificates, and quiz and assignment totals of registered users. Wi...

PoC for CVE-2026-81194

WordPressMasterstudy Lms WordPr...4.3MEDIUM
Authorization Bypass in MasterStudy LMS Plugin for WordPress

The MasterStudy LMS WordPress Plugin prior to version 3.7.46 suffers from an authorization bypass, which allows authenticated users, including low-permission roles such as Subscribers, to access other instructors' sales records. This occurs when an attacker supplies another user's identifier, lea...

PoC for CVE-2026-79621

WordPressCatalogx4.3MEDIUM
Arbitrary Content Injection Vulnerability in CatalogX WordPress Plugin

The CatalogX WordPress plugin prior to version 6.1.3 does not properly sanitize or escape user-supplied content, which allows unauthenticated users to inject arbitrary data into the product enquiry notification emails sent to site administrators. This vulnerability can lead to potential spoofing ...

PoC for CVE-2026-80467

WordPressAdvanced Custom Fields...8.1HIGH
Unauthorized Access Vulnerability in Advanced Custom Fields Plugin ...

The Advanced Custom Fields: Extended plugin for WordPress prior to version 0.9.2.7 has a vulnerability that allows unauthenticated users to submit roles through front-end user forms. This critical flaw means that the plugin does not properly restrict role submissions to the predefined roles offer...

PoC for CVE-2026-81197

WordPressMasterstudy Lms WordPr...5.3MEDIUM
Access Control Weakness in MasterStudy LMS WordPress Plugin

The MasterStudy LMS WordPress Plugin prior to version 3.7.46 has a security flaw that allows unauthorized access to a REST endpoint. This vulnerability enables unauthenticated users to view the titles and IDs of unpublished courses, including drafts, pending, and private listings. The absence of ...

PoC for CVE-2026-81196

WordPressMasterstudy Lms WordPr...2.7LOW
Insufficient Access Control in MasterStudy LMS WordPress Plugin

The MasterStudy LMS WordPress Plugin prior to version 3.7.46 suffers from an insufficient access control vulnerability that allows users with instructor access to view quiz questions, including correct answers and explanations, that belong to other instructors. This vulnerability can lead to unau...

PoC for CVE-2026-81195

WordPressMasterstudy Lms WordPr...5.3MEDIUM
Authorization Flaw in MasterStudy LMS Plugin for WordPress

The MasterStudy LMS plugin for WordPress prior to version 3.7.46 exhibits a significant authorization weakness, failing to implement necessary checks before revealing sensitive data. This vulnerability allows unauthenticated attackers to access detailed course enrollment information and progress ...

PoC for CVE-2026-78151

WordPressFormlayer5.3MEDIUM
Unauthorized Information Exposure in FormLayer Plugin for WordPress

The FormLayer plugin for WordPress prior to version 1.0.9 is susceptible to an information exposure vulnerability. It fails to implement proper authorization checks when returning form configuration details through its public submission handler. As a result, unauthenticated users can gain access ...

PoC for CVE-2026-77788

WordPressRank Math Seo4.9MEDIUM
Metadata Overwrite Vulnerability in Rank Math SEO Plugin for WordPress

The Rank Math SEO plugin for WordPress prior to version 1.0.277 contains a vulnerability that fails to properly validate the ownership of metadata updates. This oversight allows users with the Author role or higher to overwrite arbitrary metadata for posts and users, potentially affecting even hi...

PoC for CVE-2026-77783

WordPressRank Math Seo3.7LOW
Rank Math SEO Plugin Schema Exposure in WordPress

The Rank Math SEO plugin for WordPress prior to version 1.0.277 fails to enforce visibility checks for posts when rendering schema. This oversight allows unauthorized users to access and disclose schema information for draft, pending, private, scheduled, and password-protected posts. As a result,...

PoC for CVE-2026-77787

WordPressRank Math Seo2.7LOW
Unauthorized Access in Rank Math SEO Plugin for WordPress

The Rank Math SEO plugin for WordPress prior to version 1.0.277 lacks a proper capability check during bulk metadata updates targeting taxonomy terms. This weak point enables users with the Author role and above to modify SEO metadata of taxonomy terms they should not have the ability to edit. It...

PoC for CVE-2026-77792

WordPressRegistrationmagic7.5HIGH
Stored Cross-Site Scripting in RegistrationMagic WordPress Plugin

The RegistrationMagic plugin for WordPress, prior to version 6.0.9.9, is vulnerable to Stored Cross-Site Scripting (XSS) due to improper escaping of registration form field values. This vulnerability permits unauthenticated attackers to inject malicious scripts that execute in the browser of high...

PoC for CVE-2026-77784

WordPressRank Math Seo2.7LOW
Access Control Flaw in Rank Math SEO Plugin for WordPress

The Rank Math SEO WordPress plugin prior to version 1.0.277 contains an access control vulnerability that allows users with the Author role and above to edit SEO indexing metadata for content, taxonomy terms, and user profiles that they do not own. This improper validation leads to unauthorized a...

PoC for CVE-2026-77785

WordPressRank Math Seo2.7LOW
Improper Access Control in Rank Math SEO Plugin by WordPress

The Rank Math SEO plugin for WordPress prior to version 1.0.277 fails to adequately verify user permissions when accessing certain posts. This weakness permits users with Author roles and higher to retrieve content, including the title, body, and SEO metadata, from other users' private posts, the...

PoC for CVE-2026-19704

WordPressComments5.3MEDIUM
SQL Injection Vulnerability in Comments Plugin for WordPress

The Comments plugin for WordPress versions before 7.6.66 is vulnerable due to improper validation of values used in database queries. This flaw enables unauthenticated users to inject SQL code, which can reveal comments they should not have access to, such as those pending moderation, marked as s...

PoC for CVE-2026-74927

WordPressMultivendorx5.3MEDIUM
Authorization Flaw in MultiVendorX WordPress Plugin Exposes Sensiti...

The MultiVendorX WordPress plugin prior to version 5.0.15 has a significant authorization vulnerability in its REST API listings. This flaw allows unauthenticated users to access sensitive information including vendor contact details, pending payout amounts, and private administrative notes linke...

PoC for CVE-2026-77782

WordPressRank Math Seo5.3MEDIUM
Password Protection Bypass in Rank Math SEO Plugin for WordPress

The Rank Math SEO WordPress plugin prior to version 1.0.277.1 lacks proper verification for password-protected posts. This oversight allows unauthorized users to access the content of such posts, resulting in unintentional exposure of sensitive information. This vulnerability creates significant ...

PoC for CVE-2026-77764

WordPressGamipress4.3MEDIUM
Inadequate Track Restrictions in GamiPress Plugin for WordPress

The GamiPress plugin for WordPress, prior to version 7.9.9.6, contains a flaw in its video watch-tracking functionality that fails to adequately restrict access. This weakness allows users with minimal permissions, such as Subscribers, to unjustly award gamification points, achievements, and rank...

PoC for CVE-2026-19719

WordPressSocial Media Share But...6.8MEDIUM
Stored Cross-Site Scripting in Social Media Share Buttons Plugin fo...

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress prior to version 3.0.1 is susceptible to Stored Cross-Site Scripting (XSS). This vulnerability arises due to the plugin's failure to properly escape post titles before rendering them in inline JavaScript event handlers. As...

PoC for CVE-2026-19723

WordPressSocial Media Share But...7.1HIGH
Reflected Cross-Site Scripting Vulnerability in Social Media Share ...

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress, prior to version 3.0.1, contains a security flaw where it fails to properly escape user input. This weakness allows attackers to execute reflected cross-site scripting (XSS) attacks by injecting malicious scripts via an i...

PoC for CVE-2026-19453

WordPressJetbackup7.1HIGH
Improper Role Verification in JetBackup WordPress Plugin

The JetBackup plugin for WordPress, specifically versions prior to 3.1.23.5, lacks adequate checks on user role and capabilities during the restore or migration process. This flaw potentially allows users with lower privileges, such as subscribers, to escalate their access to administrator levels...

PoC for CVE-2026-19116

WordPressUser Frontend8.8HIGH
PHP Object Injection Vulnerability in User Frontend Plugin by WordP...

The User Frontend Plugin for WordPress, prior to version 4.3.11, is susceptible to a vulnerability that allows authenticated users, with subscriber-level access and above, to exploit deserialization of user-supplied input when reopening a post for editing. This can result in PHP Object Injection,...

PoC for CVE-2026-19251

WordPressUltimate Member5.3MEDIUM
Exposed Comment Activity in Ultimate Member Plugin for WordPress

The Ultimate Member plugin for WordPress prior to version 2.13.0 has a security flaw that allows unauthenticated users to access and view comments that are still awaiting moderation. This occurs because the plugin fails to verify whether a comment has been approved or whether the associated profi...

PoC for CVE-2026-16983

WordPressGutentor4.3MEDIUM
Improper Access Control in Gutentor WordPress Plugin

The Gutentor WordPress plugin prior to version 4.0.6 contains an improper access control flaw affecting its REST API endpoints. This vulnerability enables authenticated users with the Subscriber role to access plaintext passwords of password-protected posts, potentially compromising sensitive inf...

PoC for CVE-2026-16966

WordPressSolace Extra5.3MEDIUM
Authorization Flaw in Solace Extra Plugin for WordPress

The Solace Extra WordPress plugin prior to version 1.7.0 is vulnerable to an authorization bypass in one of its AJAX actions. This flaw allows unauthenticated users to gain access to the contents of non-published components—such as drafts, pending posts, private entries, and trashed items—that wo...

PoC for CVE-2026-15232

WordPressMotopress Appointment ...5.3MEDIUM
Unauthorized Deletion Vulnerability in MotoPress Appointment Bookin...

The MotoPress Appointment Booking WordPress plugin suffers from an improper access control vulnerability that allows unauthenticated attackers to delete other users' reservations. This issue arises due to a lack of necessary authorization checks when processing user-supplied booking identifiers t...

PoC for CVE-2025-15664

WordPressUltimate Before After ...6.8MEDIUM
Cross-Site Scripting in Ultimate Before After Image Slider & Galler...

The Ultimate Before After Image Slider & Gallery for WordPress lacks proper escaping of the slider's before-label value. This insufficiency allows users with Author roles and above to inject malicious payloads, which then execute in the browsers of users who view the slider, including administrat...

PoC for CVE-2026-12526

WordPressAdvanced Custom Fields...8.1HIGH
Unauthorized User Account Access in Advanced Custom Fields Plugin f...

The Advanced Custom Fields: Extended plugin prior to version 0.9.2.7 is susceptible to an authorization bypass vulnerability. This flaw allows unauthenticated users to exploit front-end forms, enabling them to tamper with user accounts, specifically targeting administrators. By manipulating the f...

PoC for CVE-2026-14215

WordPressBooking For Appointmen...6.5MEDIUM
Authentication Bypass in Booking for Appointments and Events Calend...

The Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.9 has a security flaw that permits unauthenticated users to execute the post-booking action chain without proper validation. This lapse allows malicious individuals to trigger booking notifications and exec...

PoC for CVE-2026-12865

WordPressPhoto Gallery By 10web7.1HIGH
Reflected XSS Vulnerability in Photo Gallery by 10Web Plugin for Wo...

The Photo Gallery by 10Web plugin for WordPress fails to adequately escape certain request parameters on its admin pages, specifically on the Shortcode and Galleries/Albums list pages. This oversight allows an unauthenticated attacker to craft a malicious link. When this link is accessed by a log...

PoC for CVE-2025-15663

WordPressUltimate Before After ...6.8MEDIUM
Cross-Site Scripting in Ultimate Before After Image Slider & Galler...

The Ultimate Before After Image Slider & Gallery plugin for WordPress, prior to version 4.7.19, contains a vulnerability where the plugin fails to appropriately escape the slider's after-label value during the re-injection into the DOM. This flaw can be exploited by users with Author roles and ab...

Discovered 10 hours ago

PoC for CVE-2025-62593

Ray-projectRay🟣 EPSS 17%9.4CRITICAL
Remote Code Execution Vulnerability in Ray AI Compute Engine

Ray AI Compute Engine, widely utilized as a development tool, contains a significant RCE vulnerability in versions prior to 2.52.0. This vulnerability arises from a failure to properly safeguard against browser-based attacks. The existing defense mechanism inadequately relies on the User-Agent he...

PoC for CVE-2026-13753

HP IncHP Deskjet 2820 Aio Pr...7.5HIGH
Unauthorized Access in HP Deskjet 2800 Series Printers by Embedded ...

A missing authorization vulnerability has been identified in the embedded webserver of HP Deskjet 2800 Series Printers. This issue allows an unauthenticated attacker with network access to exploit multiple exposed administrative API endpoints, potentially revealing sensitive configuration data. I...

Discovered 11 hours ago

PoC for CVE-2026-84442

MapquestGet Directions App4.8MEDIUM
Path Traversal Vulnerability in MapQuest Get Directions App on Android

A vulnerability has been discovered in the MapQuest Get Directions App version 10.16.1 for Android, specifically within the function getDataColumn located in the ExpoShareIntentModule.kt file of the component com.mapquest.android.ace. This flaw enables unauthorized access through path traversal t...

PoC for CVE-2026-84441

PiwigoPiwigo6.9MEDIUM
Path Traversal Vulnerability in Piwigo Image Derivative Handler

A vulnerability exists in the Piwigo Image Derivative Handler affecting versions up to 16.3.0, allowing attackers to exploit the i.php file through a path traversal attack. This security flaw could enable unauthorized access to system files, potentially leading to the disclosure of sensitive info...

Discovered 12 hours ago

PoC for CVE-2026-84438

OpenCartOpencart5.1MEDIUM
Cross Site Scripting Vulnerability in OpenCart Autocomplete Workflow

A cross site scripting (XSS) vulnerability has been identified in OpenCart versions 4.1.0.3 and 4.1.0.4, which is related to an unspecified function within the Autocomplete Workflow component. This vulnerability allows attackers to manipulate the 'firstname' argument in the file catalog/controlle...

PoC for CVE-2026-84437

OpenCartOpencart5.1MEDIUM
Cross Site Scripting in OpenCart Autocomplete Workflow by OpenCart

A flaw has been identified in OpenCart's Autocomplete Workflow, specifically within the address.php file located in the catalog/controller/account directory. This vulnerability allows attackers to craft malicious inputs that, when processed by the affected function, could execute arbitrary JavaSc...

PoC for CVE-2026-84431

AirasiaMove App4.8MEDIUM
Path Traversal Vulnerability in AirAsia MOVE App for Android

A path traversal vulnerability exists in the AirAsia MOVE App for Android, specifically in the function com.airasia.core.utils.RealPathUtil.getRealPath. This issue arises from improper handling of the argument _display_name, which can be manipulated by an attacker to access sensitive files outsid...

Discovered 13 hours ago

PoC for CVE-2026-84430

GouguoaGouguoa5.3MEDIUM
Remote Code Execution Vulnerability in Gouguoa Affected by Improper...

A security vulnerability exists in Gouguoa versions up to 5.10.0 and 6.0.1, specifically within the update function in app/home/controller/Index.php of the edit_personal endpoint. This flaw allows an attacker to manipulate the position_id argument, leading to the potential for dynamically-determi...

PoC for CVE-2026-82221

WordPressRegistrationmagic7.1HIGH
Cross Site Scripting Vulnerability in RegistrationMagic Plugin for ...

An unauthenticated Cross Site Scripting (XSS) vulnerability exists in the RegistrationMagic plugin for WordPress, affecting versions up to and including 6.0.9.8. This vulnerability allows attackers to inject malicious scripts into the web pages viewed by users, potentially leading to data theft, ...