Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 6 hours ago
PoC for CVE-2026-13432
The ThumbPress WordPress plugin prior to version 6.2.2 is susceptible to a security flaw where it fails to verify user capabilities on specific AJAX actions. This omission allows authenticated users with subscriber permissions or higher to deactivate the plugin. Consequently, this can lead to con...
PoC for CVE-2026-8825
The Elementor Website Builder plugin for WordPress prior to version 4.1.4 contains a flaw that allows authenticated users with Contributor-level access or higher to improperly access private post data through its REST endpoints. This vulnerability permits these users to retrieve sensitive informa...
PoC for CVE-2026-9833
The Tag Groups plugin for WordPress versions prior to 2.2.0 is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper escaping of AJAX parameters. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any logged-in user with Editor level a...
PoC for CVE-2026-13142
The Social Login, Passkeys, Magic Link & Email OTP plugin for WordPress versions prior to 1.4.1 is vulnerable due to a lack of rate limiting and absence of lockout mechanisms for its passwordless email one-time-password verification. This oversight allows attackers to exploit the security weaknes...
PoC for CVE-2026-13156
The MailerSend WordPress plugin prior to version 1.0.8 lacks a necessary nonce check for its configuration-delete action. While it verifies the manage_options capability, it fails to validate the nonce, allowing an attacker to potentially trick a logged-in administrator into visiting a maliciousl...
PoC for CVE-2026-13147
The Kirki WordPress plugin prior to version 6.0.12 is susceptible to a sever-side request forgery (SSRF) vulnerability. This issue arises because the plugin does not adequately validate URLs provided by users, potentially allowing unauthenticated attackers to initiate HTTP requests to arbitrary s...
PoC for CVE-2026-12973
The PayPlus Payment Gateway plugin for WordPress has a security flaw that allows unauthenticated users to exploit AJAX actions, leading to unauthorized access to sensitive WooCommerce order information. By bypassing necessary authorization and order-ownership checks, attackers could potentially r...
PoC for CVE-2026-12972
The PayPlus Payment Gateway plugin for WordPress, prior to version 8.2.2, has a vulnerability that permits unauthenticated users to access certain AJAX actions without proper authorization checks. This oversight allows an attacker to manipulate payment-related metadata associated with arbitrary W...
PoC for CVE-2026-12592
The SlimStat Analytics plugin for WordPress allows unauthenticated users to inject malicious scripts due to improper handling of guested geolocation values in admin analytics reports. This shortcoming can lead to the execution of XSS payloads when an administrator views these reports, particularl...
PoC for CVE-2026-12970
A vulnerability exists in the LearnPress WordPress plugin, where certain search parameters are not adequately escaped before being rendered in HTML attributes. This oversight can lead to reflected cross-site scripting (XSS) attacks, which may execute malicious scripts in the browsers of users, pa...
PoC for CVE-2026-12723
The Kirki WordPress plugin prior to version 6.0.12 contains a significant vulnerability in that it fails to implement necessary authorization checks on one of its REST routes. This oversight permits unauthenticated users to not only overwrite existing comments but also to create comments that are...
PoC for CVE-2026-12724
The Kirki WordPress plugin prior to version 6.0.12 is vulnerable due to inadequate sanitization and escaping of the email subject and body inputs. This flaw enables unauthorized users to inject arbitrary HTML code into the password-reset emails sent to registered users, thereby exposing them to p...
PoC for CVE-2026-12898
The All-in-One WP Migration and Backup plugin for WordPress prior to version 7.106 contains an improper input validation flaw. This vulnerability allows unauthenticated attackers to create or append log files in arbitrary locations outside of the intended storage directory. The plugin fails to pr...
PoC for CVE-2026-10755
The All in One SEO plugin for WordPress prior to version 4.9.9 has a security issue where it fails to properly restrict access to certain AI integration REST API endpoints. This flaw allows users with minimum privileges, such as Contributors, the potential to overwrite or reset critical site-wide...
PoC for CVE-2026-11349
The Modern Event Calendar Pro and Lite plugins for WordPress are vulnerable due to improper sanitization and escaping of request parameters used in SQL statements during an AJAX action. This weakness allows unauthenticated users to exploit the vulnerabilities, leading to unauthorized access to da...
PoC for CVE-2026-11868
The WP Travel plugin for WordPress prior to version 11.7.1 is susceptible to an unauthorized action vulnerability that permits unauthenticated users to cancel any booking on the site. The plugin fails to implement necessary capability and ownership checks during the booking cancellation process, ...
PoC for CVE-2026-10724
The Reviews Feed, a plugin for WordPress, fails to sanitize WordPress shortcodes present in third-party review content before rendering them via its dynamic block. This oversight permits unauthenticated attackers to execute arbitrary shortcodes on any pages displaying the feed, potentially compro...
PoC for CVE-2026-10081
The Unlimited Elements for Elementor WordPress plugin, prior to version 2.0.11, fails to properly sanitize or escape content fetched from the Google Serp API. This vulnerability allows unauthenticated attackers to submit malicious reviews to a targeted business's Google listing. When these review...
Discovered 9 hours ago
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
Discovered 10 hours ago
PoC for CVE-2026-45585
A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...
Discovered 17 hours ago
PoC for CVE-2025-64512
Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...
PoC for CVE-2026-33017
Langflow, a tool for constructing and deploying AI-driven agents and workflows, is susceptible to a vulnerability in the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint in versions before 1.9.0. This vulnerability enables an attacker to build public flows without authentication, leveraging ...
Discovered 18 hours ago
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
Discovered 21 hours ago
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
Discovered 22 hours ago
PoC for CVE-2026-46215
A race condition has been identified in the Linux kernel related to the handling of device resources, specifically within the Direct Rendering Manager (DRM). This vulnerability arises during the prime swap operation where a single object can spawn two ID references. A concurrent operation, such a...
Discovered 1 day ago
PoC for CVE-2026-16229
A flaw has been identified in the itsourcecode Courier Management System that can be exploited through remote manipulation of the 'page' argument in the /index.php file. This vulnerability allows attackers to execute cross site scripting attacks, potentially leading to unauthorized actions on beh...
PoC for CVE-2026-16228
A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the /edit_schoolyr.php file. This flaw allows attackers to manipulate the ID argument, leading to SQL injection attacks that can be executed remotely. As a result,...
PoC for CVE-2026-16227
A security flaw has been identified in version 1.0 of the SourceCodester Class and Exam Timetabling System. This vulnerability resides within an unspecified function of the /edit_subject.php file, where it is possible for an attacker to manipulate the ID argument. This manipulation can lead to un...
PoC for CVE-2026-16225
A significant security flaw exists in Snap7 by Davenardella affecting the function TSnap7Peer::NegotiatePDULength within the s7_peer.cpp file. The vulnerability arises from improper handling of the PDULength argument, leading to an out-of-bounds write condition. This flaw can be exploited remotel...
PoC for CVE-2026-46420
The setup-php action, which simplifies the configuration of PHP environments on GitHub Actions, is vulnerable to command injection due to its handling of PHP version resolution from certain repository-controlled files. Specifically, from versions 2.25.0 to 2.37.0, inadequate validation of version...
PoC for CVE-2026-16223
A vulnerability exists in 1Panel-dev CordysCRM versions up to 1.4.1, specifically within the getSqlBotSrc function of the IntegrationConfigService.java file. This flaw allows an attacker to manipulate the appSecret argument, potentially leading to unauthorized server-side requests being executed....
PoC for CVE-2026-16222
A potential security vulnerability exists within 1Panel-dev CordysCRM, specifically affecting the TokenService component found in the backend/crm/src/main/java/cn/cordys/crm/integration/sso/service directory. By manipulating the mkAddress argument, an attacker may execute server-side request forg...
PoC for CVE-2026-60137
A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...
PoC for CVE-2026-16220
The Online Examination System version 1.0 developed by Code-Projects contains a cross-site scripting vulnerability in the /account.php file, particularly when manipulating the 'eid/n/t' argument. This weakness allows an attacker to execute arbitrary JavaScript in the context of the user's browser...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-16219
A vulnerability has been identified in Croogo CMS versions up to 4.0.7, specifically within the FileManager::isEditable function located in FileManager/src/Utility/FileManager.php. This flaw allows an attacker to perform path traversal attacks, which can lead to unauthorized access to sensitive f...
PoC for CVE-2026-16217
A security vulnerability has been identified in the Guohongze Adminset version up to 0.61, specifically within the Delivery Deployment Endpoint's deli.py file. The vulnerability lies in how the project_id argument is processed, potentially allowing unauthorized access. This issue can be exploited...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-16216
A vulnerability has been discovered in the OAuth Handler of Geex-Arts Django-Jet, affecting versions up to 1.0.8. This issue allows remote attackers to manipulate the handler and potentially execute cross-site request forgery attacks. Although the problem was reported early, the vendor has not ta...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-60137
A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...
PoC for CVE-2026-16212
A race condition vulnerability has been discovered in awesto django-shop, specifically affecting version 1.2.4. This vulnerability resides in the Purchase Stock Handler component located in shop/models/inventory.py. The flaw can be exploited remotely, indicating a potential risk to users of the s...
PoC for CVE-2021-3129
Ignition versions prior to 2.5.2, as utilized in Laravel, may expose applications to remote code execution vulnerabilities. Attackers can exploit this weakness by leveraging insecure file handling functions, particularly when applications are run in debug mode. This allows unauthenticated attacke...
PoC for CVE-2026-16211
A vulnerability has been identified in Allegro's Ralph, specifically in the Hostname Allocation Handler. The issue resides in the AssetLastHostname.increment_hostname function of the assets.py file. By manipulating the argument counter, an attacker could potentially exploit a race condition. Thou...
PoC for CVE-2026-16210
A vulnerability exists in the AjaxAdmin component of newpanjing SimpleUI (version 2026.01.13), where the function 'self.get_action' located in simpleui/admin.py allows for missing authentication. This flaw may enable unauthorized remote exploitation, posing a significant risk to users. The projec...
PoC for CVE-2026-16209
A vulnerability exists in Gerapy versions up to 0.9.13, specifically in the Project Upload Endpoint. This issue arises from a missing authentication mechanism in the file gerapy/server/core/views.py. Attackers can remotely exploit this vulnerability to manipulate the endpoint without proper verif...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-16205
A potential cross-site scripting (XSS) vulnerability exists in the Albums Module of Pluck CMS versions up to 4.7.21. The issue arises from improper handling of user input in the htmlspecialchars_decode function within the file data/modules/albums/albums.admin.php. By manipulating the argument Inf...
PoC for CVE-2026-16204
A security flaw has been identified in the zevorn rt-claw product, specifically in the Telegram-to-AI Tool Execution Flow's tool_run_script_execute function. This vulnerability allows for remote code injection due to inadequate input validation in the script handling mechanism found in claw/servi...