<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Account-Takeover — PoC Archive</title><link>https://poc.intelseclab.com/tags/account-takeover/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/account-takeover/index.xml" rel="self" type="application/rss+xml"/><item><title>WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-13390. Status: Weaponized. Affects: WP Directory Kit (WordPress plugin). Tags: wordpress, wp-directory-kit, authentication-bypass, predictable-token, account-takeover, webshell-upload, python, cwe-287.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-directory-kit</category><category>authentication-bypass</category><category>predictable-token</category><category>account-takeover</category><category>webshell-upload</category><category>python</category><category>cwe-287</category></item><item><title>Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-53580-sbd-password-reset-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-53580-sbd-password-reset-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-53580. Status: Weaponized. Affects: quantumcloud "Simple Business Directory Pro" WordPress plugin (simple-business-directory-pro). Tags: wordpress, wordpress-plugin, simple-business-directory-pro, password-reset, privilege-escalation, incorrect-privilege-assignment, cwe-266, account-takeover, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>simple-business-directory-pro</category><category>password-reset</category><category>privilege-escalation</category><category>incorrect-privilege-assignment</category><category>cwe-266</category><category>account-takeover</category><category>unauthenticated</category><category>python</category></item><item><title>RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-9209. Status: Weaponized. Affects: RestroPress – Online Food Ordering System (WordPress plugin). Tags: restropress, wordpress, wordpress-plugin, information-exposure, jwt, authentication-bypass, account-takeover, rest-api, mass-scanner, cwe-200, cwe-287, python.</description><category>web</category><category>Critical</category><category>restropress</category><category>wordpress</category><category>wordpress-plugin</category><category>information-exposure</category><category>jwt</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>mass-scanner</category><category>cwe-200</category><category>cwe-287</category><category>python</category></item><item><title>PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61922-prestashop-checkout-account-takeover/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61922-prestashop-checkout-account-takeover/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-61922. Status: PoC. Affects: PrestaShop Checkout module (ps_checkout). Tags: prestashop, ps_checkout, account-takeover, express-checkout, paypal, zero-click, session-hijacking, e-commerce, cwe-287.</description><category>web</category><category>Critical</category><category>prestashop</category><category>ps_checkout</category><category>account-takeover</category><category>express-checkout</category><category>paypal</category><category>zero-click</category><category>session-hijacking</category><category>e-commerce</category><category>cwe-287</category></item><item><title>FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-58434-flowise-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-58434-flowise-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-58434. Status: Weaponized. Affects: FlowiseAI (/api/v1/account/forgot-password and /api/v1/account/reset-password endpoints). Tags: flowiseai, auth-bypass, account-takeover, forgot-password, reset-password, api, python, cwe-640.</description><category>web</category><category>Critical</category><category>flowiseai</category><category>auth-bypass</category><category>account-takeover</category><category>forgot-password</category><category>reset-password</category><category>api</category><category>python</category><category>cwe-640</category></item><item><title>Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39912-xboard-v2board-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39912-xboard-v2board-account-takeover/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-39912. Status: Weaponized. Affects: V2Board / Xboard (VPN/proxy subscription management panels). Tags: xboard, v2board, php, laravel, account-takeover, magic-link, unauthenticated, information-disclosure, proxy-panel.</description><category>web</category><category>Critical</category><category>xboard</category><category>v2board</category><category>php</category><category>laravel</category><category>account-takeover</category><category>magic-link</category><category>unauthenticated</category><category>information-disclosure</category><category>proxy-panel</category></item><item><title>WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5415-wp-captcha-pro-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5415-wp-captcha-pro-auth-bypass/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-5415. Status: PoC. Affects: WP Captcha PRO (WordPress plugin, Advanced Google reCAPTCHA). Tags: wordpress, wp-captcha-pro, auth-bypass, privilege-escalation, nonce, ajax, account-takeover, plugin.</description><category>web</category><category>High</category><category>wordpress</category><category>wp-captcha-pro</category><category>auth-bypass</category><category>privilege-escalation</category><category>nonce</category><category>ajax</category><category>account-takeover</category><category>plugin</category></item><item><title>WordPress SignUp/SignIn &amp; Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-12416-wp-password-reset-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-12416-wp-password-reset-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-12416, CVE-2026-12417. Status: Weaponized. Affects: SignUp &amp; SignIn WordPress plugin (CVE-2026-12417); Invoice Generator WordPress plugin (CVE-2026-12416). Tags: wordpress, wp-plugin, account-takeover, password-reset, auth-bypass, ajax, mass-exploitation.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>account-takeover</category><category>password-reset</category><category>auth-bypass</category><category>ajax</category><category>mass-exploitation</category></item><item><title>Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37072-veno-file-manager-superadmin-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37072-veno-file-manager-superadmin-takeover/</guid><description>Critical severity — web · CVE-2026-37072. Status: PoC. Affects: Veno File Manager Project. Tags: file-manager, unauthenticated, local-file-inclusion, account-takeover, php, veno-file-manager.</description><category>web</category><category>Critical</category><category>file-manager</category><category>unauthenticated</category><category>local-file-inclusion</category><category>account-takeover</category><category>php</category><category>veno-file-manager</category></item><item><title>Tornet Scooter Mobile App OTP Brute Force via Missing Rate Limiting (CVE-2026-7671)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7671-tornet-scooter-otp-bruteforce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7671-tornet-scooter-otp-bruteforce/</guid><description>Medium severity — web · CVE-2026-7671. Status: PoC. Affects: Tornet Scooter Mobile App backend (/TwoFactor endpoint), Android app v4.75. Tags: tornet-scooter, otp-bruteforce, missing-rate-limiting, cwe-307, mobile-backend, account-takeover.</description><category>web</category><category>Medium</category><category>tornet-scooter</category><category>otp-bruteforce</category><category>missing-rate-limiting</category><category>cwe-307</category><category>mobile-backend</category><category>account-takeover</category></item><item><title>Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27886-strapi-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27886-strapi-account-takeover/</guid><description>Critical severity — web · CVE-2026-27886. Status: Weaponized. Affects: Strapi CMS (Content API). Tags: strapi, cms, account-takeover, password-reset, boolean-oracle, api-filter-bypass, authentication.</description><category>web</category><category>Critical</category><category>strapi</category><category>cms</category><category>account-takeover</category><category>password-reset</category><category>boolean-oracle</category><category>api-filter-bypass</category><category>authentication</category></item><item><title>SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23760-smartermail-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23760-smartermail-auth-bypass/</guid><description>Critical severity (CVSS 9.3) — web · CVE-2026-23760. Status: PoC. Affects: SmarterTools SmarterMail. Tags: smartermail, authentication-bypass, password-reset, account-takeover, rce, email-server, watchtowr.</description><category>web</category><category>Critical</category><category>smartermail</category><category>authentication-bypass</category><category>password-reset</category><category>account-takeover</category><category>rce</category><category>email-server</category><category>watchtowr</category></item><item><title>Simple History Missing Authorization Account Takeover — CVE-2026-7459</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7459-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7459-poc/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-7459. Status: PoC. Affects: Simple History (WordPress plugin). Tags: wordpress, simple-history, broken-access-control, account-takeover, rest-api, password-reset.</description><category>web</category><category>High</category><category>wordpress</category><category>simple-history</category><category>broken-access-control</category><category>account-takeover</category><category>rest-api</category><category>password-reset</category></item><item><title>Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40487-postiz-svg-upload-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40487-postiz-svg-upload-xss/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-40487 / GHSA-44wg-r34q-hvfx. Status: PoC. Affects: Postiz (open-source social media management platform, gitroomhq/postiz-app). Tags: file-upload, mime-spoofing, stored-xss, account-takeover, postiz, nodejs, oauth-backdoor.</description><category>web</category><category>High</category><category>file-upload</category><category>mime-spoofing</category><category>stored-xss</category><category>account-takeover</category><category>postiz</category><category>nodejs</category><category>oauth-backdoor</category></item><item><title>PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44166-pocketbase-oauth2-account-prehijack/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44166-pocketbase-oauth2-account-prehijack/</guid><description>Medium severity (CVSS 6.1) — web · CVE-2026-44166 / [GHSA-pq7p-mc74-g65w](https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w). Status: PoC. Affects: [PocketBase](https://github.com/pocketbase/pocketbase) (Go backend / BaaS). Tags: pocketbase, oauth2, account-takeover, account-pre-hijacking, cwe-287, improper-authentication, go.</description><category>web</category><category>Medium</category><category>pocketbase</category><category>oauth2</category><category>account-takeover</category><category>account-pre-hijacking</category><category>cwe-287</category><category>improper-authentication</category><category>go</category></item><item><title>LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6741-latepoint-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6741-latepoint-privesc/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-6741. Status: PoC. Affects: LatePoint – Calendar Booking Plugin for Appointments and Events (WordPress plugin, slug latepoint). Tags: wordpress, latepoint, privilege-escalation, abilities-api, rest-api, account-takeover, cwe-269.</description><category>web</category><category>High</category><category>wordpress</category><category>latepoint</category><category>privilege-escalation</category><category>abilities-api</category><category>rest-api</category><category>account-takeover</category><category>cwe-269</category></item><item><title>Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8206-kirki-password-reset-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8206-kirki-password-reset-takeover/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-8206. Status: PoC. Affects: Kirki (WordPress Customizer framework plugin) — CompLibFormHandler REST API endpoint. Tags: wordpress, kirki, account-takeover, password-reset-hijack, unauthenticated, rest-api.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kirki</category><category>account-takeover</category><category>password-reset-hijack</category><category>unauthenticated</category><category>rest-api</category></item><item><title>Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10580-hippoo-woocommerce-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10580-hippoo-woocommerce-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-10580. Status: Weaponized. Affects: Hippoo Mobile App for WooCommerce (WordPress plugin). Tags: wordpress, plugin, woocommerce, hippoo, authentication-bypass, account-takeover, rest-api, unauthenticated.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>woocommerce</category><category>hippoo</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>unauthenticated</category></item><item><title>Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-52813-gogs-path-traversal-hook-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-52813-gogs-path-traversal-hook-rce/</guid><description>Info severity — web · CVE-2026-52813. Status: PoC. Affects: Gogs (self-hosted Git service), organization creation feature. Tags: gogs, path-traversal, git-hooks, rce, authenticated, account-takeover, self-hosted-git.</description><category>web</category><category>Info</category><category>gogs</category><category>path-traversal</category><category>git-hooks</category><category>rce</category><category>authenticated</category><category>account-takeover</category><category>self-hosted-git</category></item><item><title>FOSSBilling Unauthenticated API Key Config Disclosure &amp; Password Reset Token Reuse — CVE-2026-53647</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-53647-fossbilling-chained-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-53647-fossbilling-chained-rce/</guid><description>Medium severity (CVSS 6.9) — web · CVE-2026-53647 (also documents chained CVE-2026-53646). Status: PoC. Affects: FOSSBilling (open-source billing/client management platform). Tags: fossbilling, api-key-disclosure, password-reset, token-reuse, account-takeover, unauthenticated, ghsa, php.</description><category>web</category><category>Medium</category><category>fossbilling</category><category>api-key-disclosure</category><category>password-reset</category><category>token-reuse</category><category>account-takeover</category><category>unauthenticated</category><category>ghsa</category><category>php</category></item><item><title>Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5229-form-notify-line-oauth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5229-form-notify-line-oauth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-5229. Status: PoC. Affects: Form Notify WordPress plugin, LINE Login OAuth 2.0 integration (src/APIs/Line/Login/Route.php, User.php). Tags: wordpress, form-notify, oauth, line-login, authentication-bypass, account-takeover, cookie-injection, cve-2026-5229.</description><category>web</category><category>Critical</category><category>wordpress</category><category>form-notify</category><category>oauth</category><category>line-login</category><category>authentication-bypass</category><category>account-takeover</category><category>cookie-injection</category><category>cve-2026-5229</category></item><item><title>Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</guid><description>Critical severity — web · CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11). Status: PoC. Affects: Discuz! X5.0 (PHP-based forum/CMS software). Tags: discuz, php, forum, race-condition, captcha-bypass, ocr, account-takeover, lfi, webshell, rce, pre-auth.</description><category>web</category><category>Critical</category><category>discuz</category><category>php</category><category>forum</category><category>race-condition</category><category>captcha-bypass</category><category>ocr</category><category>account-takeover</category><category>lfi</category><category>webshell</category><category>rce</category><category>pre-auth</category></item><item><title>Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8181-burst-statistics-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8181-burst-statistics-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-8181. Status: PoC. Affects: Burst Statistics – Privacy-Friendly WordPress Analytics (burst-statistics plugin). Tags: wordpress, burst-statistics, authentication-bypass, cwe-287, application-password, account-takeover, mainwp.</description><category>web</category><category>Critical</category><category>wordpress</category><category>burst-statistics</category><category>authentication-bypass</category><category>cwe-287</category><category>application-password</category><category>account-takeover</category><category>mainwp</category></item><item><title>Branda White Label &amp; Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-11551-branda-wp-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-11551-branda-wp-account-takeover/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-11551. Status: Weaponized. Affects: Branda White Label &amp; Branding WordPress plugin. Tags: wordpress, plugin, account-takeover, privilege-escalation, unauthenticated, multisite, branda.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>account-takeover</category><category>privilege-escalation</category><category>unauthenticated</category><category>multisite</category><category>branda</category></item><item><title>Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54415-azuriom-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54415-azuriom-account-takeover/</guid><description>High severity (CVSS 3.1) — web · CVE-2026-54415. Status: PoC. Affects: Azuriom CMS. Tags: azuriom, cms, broken-access-control, cwe-862, cwe-269, privilege-escalation, account-takeover, php, laravel, azlink.</description><category>web</category><category>High</category><category>azuriom</category><category>cms</category><category>broken-access-control</category><category>cwe-862</category><category>cwe-269</category><category>privilege-escalation</category><category>account-takeover</category><category>php</category><category>laravel</category><category>azlink</category></item><item><title>ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5076-armember-password-reset-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5076-armember-password-reset-takeover/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074). Status: PoC. Affects: ARMember – Membership Plugin &amp; Content Restriction (WordPress plugin). Tags: wordpress, armember, membership-plugin, sql-injection, password-reset, plaintext-key, account-takeover, cwe-640.</description><category>web</category><category>Critical</category><category>wordpress</category><category>armember</category><category>membership-plugin</category><category>sql-injection</category><category>password-reset</category><category>plaintext-key</category><category>account-takeover</category><category>cwe-640</category></item></channel></rss>