<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Admin-Takeover — PoC Archive</title><link>https://poc.intelseclab.com/tags/admin-takeover/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/admin-takeover/index.xml" rel="self" type="application/rss+xml"/><item><title>Sneeit Framework &lt;= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6389-wordpress-rogue-admin-user-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6389-wordpress-rogue-admin-user-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6389. Status: Weaponized. Affects: Sneeit Framework (WordPress theme framework plugin, sneeit-framework). Tags: wordpress, sneeit-framework, rce, call_user_func, unauthenticated, wp_insert_user, privilege-escalation, admin-takeover, cwe-94, wp-ajax-nopriv.</description><category>web</category><category>Critical</category><category>wordpress</category><category>sneeit-framework</category><category>rce</category><category>call_user_func</category><category>unauthenticated</category><category>wp_insert_user</category><category>privilege-escalation</category><category>admin-takeover</category><category>cwe-94</category><category>wp-ajax-nopriv</category></item><item><title>Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13342-frontend-admin-unauth-admin-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13342-frontend-admin-unauth-admin-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13342. Status: Weaponized. Affects: Frontend Admin by DynamiApps (WordPress plugin built on Advanced Custom Fields / ACF frontend forms). Tags: wordpress, wordpress-plugin, frontend-admin, dynamiapps, acf, advanced-custom-fields, broken-access-control, cwe-284, privilege-escalation, unauthenticated, admin-takeover, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>frontend-admin</category><category>dynamiapps</category><category>acf</category><category>advanced-custom-fields</category><category>broken-access-control</category><category>cwe-284</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-takeover</category><category>python</category></item><item><title>WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40791-wp-time-slots-booking-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40791-wp-time-slots-booking-xss/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-40791. Status: PoC. Affects: WP Time Slots Booking Form (wp-time-slots-booking-form WordPress plugin). Tags: wordpress, wordpress-plugin, stored-xss, unauthenticated, cwe-79, admin-takeover, booking-form.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-plugin</category><category>stored-xss</category><category>unauthenticated</category><category>cwe-79</category><category>admin-takeover</category><category>booking-form</category></item><item><title>WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54807-woocommerce-reg-admin-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54807-woocommerce-reg-admin-privesc/</guid><description>Info severity — web · CVE-2026-54807. Status: PoC. Affects: WordPress plugin exposing a custom WooCommerce-style frontend registration form (form fields prefixed tgwcfb_*). Tags: wordpress, woocommerce, privilege-escalation, registration-form, admin-takeover, broken-access-control.</description><category>web</category><category>Info</category><category>wordpress</category><category>woocommerce</category><category>privilege-escalation</category><category>registration-form</category><category>admin-takeover</category><category>broken-access-control</category></item><item><title>User Registration &amp; Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1492-user-registration-membership-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1492-user-registration-membership-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-1492. Status: Weaponized. Affects: User Registration &amp; Membership WordPress plugin (Custom Registration Form Builder, Login Form, User Profile, Content Restriction &amp; Membership). Tags: wordpress, privilege-escalation, unauthenticated, ajax, membership-plugin, admin-takeover, cwe-269.</description><category>web</category><category>Critical</category><category>wordpress</category><category>privilege-escalation</category><category>unauthenticated</category><category>ajax</category><category>membership-plugin</category><category>admin-takeover</category><category>cwe-269</category></item><item><title>UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation &amp; RCE (CVE-2026-10795)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10795-updraftplus-rpc-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10795-updraftplus-rpc-rce/</guid><description>Critical severity — web · CVE-2026-10795. Status: Weaponized. Affects: UpdraftPlus (WordPress backup plugin) — UpdraftCentral remote RPC feature. Tags: wordpress, plugin, updraftplus, rpc, unauthenticated, admin-takeover, plugin-upload, rce, mass-exploitation.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>updraftplus</category><category>rpc</category><category>unauthenticated</category><category>admin-takeover</category><category>plugin-upload</category><category>rce</category><category>mass-exploitation</category></item><item><title>LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0920-lakit-elementor-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0920-lakit-elementor-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-0920. Status: Weaponized. Affects: LA-Studio Element Kit for Elementor (WordPress plugin, slug lakit). Tags: wordpress, plugin, elementor, privilege-escalation, admin-takeover, unauthenticated, ajax, wp-ajax.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>elementor</category><category>privilege-escalation</category><category>admin-takeover</category><category>unauthenticated</category><category>ajax</category><category>wp-ajax</category></item><item><title>Divi Form Builder &lt;= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5118-divi-form-builder-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5118-divi-form-builder-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-5118. Status: PoC. Affects: Divi Form Builder (WordPress plugin). Tags: wordpress, divi-form-builder, privilege-escalation, role-injection, cwe-266, unauthenticated, admin-takeover, nonce-reuse.</description><category>web</category><category>Critical</category><category>wordpress</category><category>divi-form-builder</category><category>privilege-escalation</category><category>role-injection</category><category>cwe-266</category><category>unauthenticated</category><category>admin-takeover</category><category>nonce-reuse</category></item><item><title>AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1729-adforest-wp-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1729-adforest-wp-auth-bypass/</guid><description>Critical severity — web · CVE-2026-1729. Status: PoC. Affects: AdForest theme for WordPress. Tags: wordpress, adforest-theme, authentication-bypass, otp-login, ajax, admin-takeover, unauthenticated.</description><category>web</category><category>Critical</category><category>wordpress</category><category>adforest-theme</category><category>authentication-bypass</category><category>otp-login</category><category>ajax</category><category>admin-takeover</category><category>unauthenticated</category></item><item><title>Gogs Admin User Edit CSRF to Git Hook RCE</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_gogs-admin-csrf-git-hook-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_gogs-admin-csrf-git-hook-rce/</guid><description>Critical severity — web · None assigned as of 2026-07-03. Status: Weaponized. Affects: Gogs (self-hosted Git service). Tags: gogs, csrf, git-hooks, privilege-escalation, rce, admin-takeover, git, self-hosted.</description><category>web</category><category>Critical</category><category>gogs</category><category>csrf</category><category>git-hooks</category><category>privilege-escalation</category><category>rce</category><category>admin-takeover</category><category>git</category><category>self-hosted</category></item></channel></rss>