PoC Archive PoC Archive

tag

Account-Takeover

Critical
WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
CVE-2025-13390· WP Directory Kit (WordPress plugin) unpatched
Critical
Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580· quantumcloud "Simple Business Directory Pro" WordPress plugin (simple-business-directory-pro) patched
Critical
RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209· RestroPress – Online Food Ordering System (WordPress plugin) unpatched
Critical
PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
CVE-2025-61922· PrestaShop Checkout module (ps_checkout) unpatched
Critical
FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)
CVE-2025-58434· FlowiseAI (/api/v1/account/forgot-password and /api/v1/account/reset-password endpoints) unpatched
Critical
Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
CVE-2026-39912· V2Board / Xboard (VPN/proxy subscription management panels) unpatched
High
WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415· WP Captcha PRO (WordPress plugin, Advanced Google reCAPTCHA) unpatched
Critical
WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
CVE-2026-12416, CVE-2026-12417· SignUp & SignIn WordPress plugin (CVE-2026-12417); Invoice Generator WordPress plugin (CVE-2026-12416) unpatched
Critical
Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
CVE-2026-37072· Veno File Manager Project unpatched
Medium
Tornet Scooter Mobile App OTP Brute Force via Missing Rate Limiting (CVE-2026-7671)
CVE-2026-7671· Tornet Scooter Mobile App backend (/TwoFactor endpoint), Android app v4.75 unpatched
Critical
Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
CVE-2026-27886· Strapi CMS (Content API) unpatched
Critical
SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760)
CVE-2026-23760· SmarterTools SmarterMail patched
High
Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459· Simple History (WordPress plugin) unpatched
High
Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)
CVE-2026-40487 / GHSA-44wg-r34q-hvfx· Postiz (open-source social media management platform, gitroomhq/postiz-app) patched
Medium
PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)
CVE-2026-44166 / [GHSA-pq7p-mc74-g65w](https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w)· [PocketBase](https://github.com/pocketbase/pocketbase) (Go backend / BaaS) unpatched
High
LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
CVE-2026-6741· LatePoint – Calendar Booking Plugin for Appointments and Events (WordPress plugin, slug latepoint) patched
Critical
Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
CVE-2026-8206· Kirki (WordPress Customizer framework plugin) — CompLibFormHandler REST API endpoint unpatched
Critical
Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580· Hippoo Mobile App for WooCommerce (WordPress plugin) unpatched
Not disclosed
Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
CVE-2026-52813· Gogs (self-hosted Git service), organization creation feature patched
Moderate
FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 (also documents chained CVE-2026-53646)· FOSSBilling (open-source billing/client management platform) patched
Critical
Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
CVE-2026-5229· Form Notify WordPress plugin, LINE Login OAuth 2.0 integration (src/APIs/Line/Login/Route.php, User.php) patched
Critical
Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11)· Discuz! X5.0 (PHP-based forum/CMS software) unpatched
Critical
Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181)
CVE-2026-8181· Burst Statistics – Privacy-Friendly WordPress Analytics (burst-statistics plugin) patched
Critical
Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551· Branda White Label & Branding WordPress plugin patched
High
Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415· Azuriom CMS patched
Critical
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074)· ARMember – Membership Plugin & Content Restriction (WordPress plugin) patched