<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Arbitrary-File-Upload — PoC Archive</title><link>https://poc.intelseclab.com/tags/arbitrary-file-upload/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/arbitrary-file-upload/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-39401. Status: Weaponized. Affects: WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla. Tags: wordpress, wpams, mojoomla, arbitrary-file-upload, webshell, rce, unauthenticated, python, multithreaded, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpams</category><category>mojoomla</category><category>arbitrary-file-upload</category><category>webshell</category><category>rce</category><category>unauthenticated</category><category>python</category><category>multithreaded</category><category>cwe-434</category></item><item><title>WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12057. Status: Weaponized. Affects: WavePlayer (WordPress plugin). Tags: wordpress, waveplayer, arbitrary-file-upload, unauthenticated, rce, webshell, ajax, nonce, php, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>waveplayer</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>webshell</category><category>ajax</category><category>nonce</category><category>php</category><category>python</category></item><item><title>StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-7441. Status: PoC. Affects: StoryChief WordPress plugin. Tags: storychief, wordpress, wordpress-plugin, arbitrary-file-upload, ssrf, remote-code-execution, unauthenticated, webhook, hmac, cwe-434, python.</description><category>web</category><category>Critical</category><category>storychief</category><category>wordpress</category><category>wordpress-plugin</category><category>arbitrary-file-upload</category><category>ssrf</category><category>remote-code-execution</category><category>unauthenticated</category><category>webhook</category><category>hmac</category><category>cwe-434</category><category>python</category></item><item><title>StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-48148. Status: Weaponized. Affects: StoreKeeper for WooCommerce (WordPress plugin). Tags: wordpress, woocommerce, storekeeper, arbitrary-file-upload, unauthenticated, webshell, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>storekeeper</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4632-magicinfo-path-traversal-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4632-magicinfo-path-traversal-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-4632. Status: Weaponized. Affects: Samsung MagicINFO 9 Server (digital signage content management server), SWUpdateFileUploader servlet. Tags: samsung, magicinfo, path-traversal, arbitrary-file-upload, unauthenticated-rce, jsp-webshell, cwe-22, cwe-434, python.</description><category>web</category><category>Critical</category><category>samsung</category><category>magicinfo</category><category>path-traversal</category><category>arbitrary-file-upload</category><category>unauthenticated-rce</category><category>jsp-webshell</category><category>cwe-22</category><category>cwe-434</category><category>python</category></item><item><title>KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12674. Status: Weaponized. Affects: KiotViet Sync (WordPress plugin). Tags: wordpress, kiotviet-sync, arbitrary-file-upload, unauthenticated, rce, rest-api, webshell, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kiotviet-sync</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>rest-api</category><category>webshell</category><category>python</category></item><item><title>Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49071-flozen-theme-arbitrary-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49071-flozen-theme-arbitrary-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49071. Status: Weaponized. Affects: Flozen Theme for WordPress. Tags: wordpress, flozen-theme, arbitrary-file-upload, unauthenticated, webshell, zip-upload, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>flozen-theme</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>zip-upload</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>WPvivid Backup &amp; Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1357-wpvivid-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1357-wpvivid-file-upload-rce/</guid><description>Critical severity — web · CVE-2026-1357. Status: Weaponized. Affects: WPvivid Backup &amp; Migration WordPress plugin. Tags: wordpress, wpvivid, arbitrary-file-upload, rce, unauthenticated, cryptography, path-traversal.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpvivid</category><category>arbitrary-file-upload</category><category>rce</category><category>unauthenticated</category><category>cryptography</category><category>path-traversal</category></item><item><title>WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1555-webstack-wp-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1555-webstack-wp-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-1555. Status: Weaponized. Affects: WebStack theme for WordPress. Tags: wordpress, webstack-theme, arbitrary-file-upload, unauthenticated-rce, webshell, ajax, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>webstack-theme</category><category>arbitrary-file-upload</category><category>unauthenticated-rce</category><category>webshell</category><category>ajax</category><category>cwe-434</category></item><item><title>Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21627-joomla-nrframework-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21627-joomla-nrframework-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-21627. Status: Weaponized. Affects: plg_system_nrframework (Tassos/Novarain Framework) Joomla plugin, bundled with Convert Forms, Engage Box, Google Structured Data, and other Tassos.gr extensions. Tags: joomla, nrframework, file-inclusion, unauthenticated, arbitrary-file-upload, arbitrary-file-delete, php, cms.</description><category>web</category><category>Critical</category><category>joomla</category><category>nrframework</category><category>file-inclusion</category><category>unauthenticated</category><category>arbitrary-file-upload</category><category>arbitrary-file-delete</category><category>php</category><category>cms</category></item><item><title>EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1657-eventprime-wp-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1657-eventprime-wp-file-upload/</guid><description>Medium severity — web · CVE-2026-1657. Status: PoC. Affects: EventPrime (WordPress plugin). Tags: wordpress, eventprime, arbitrary-file-upload, unauthenticated, ajax, media-library, cwe-434.</description><category>web</category><category>Medium</category><category>wordpress</category><category>eventprime</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>ajax</category><category>media-library</category><category>cwe-434</category></item></channel></rss>